create-pipeline

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's capabilities are largely aligned with its stated CI/CD purpose, but its trust model is weaker than ideal because it relies on a credentialed MCP runtime whose V2 provenance is somewhat ambiguous in the official docs. Risk is driven more by supply-chain and credential-forwarding concerns than by malicious behavior in the skill itself.

Confidence: 85%Severity: 57%
Audit Metadata
Analyzed At
Apr 1, 2026, 06:18 AM
Package URL
pkg:socket/skills-sh/harness%2Fharness-skills%2Fcreate-pipeline%2F@8bc3ee243ef3ed113fb538c80de810ca3ab08a71
Security Audit — socket — create-pipeline