harness-initializer

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is mostly aligned with its stated purpose and uses Archon in a coherent way, but it grants broad autonomous setup powers: executing unspecified local init scripts, writing files, updating external project state, and committing all repo contents. No clear malware or credential-harvesting behavior is present, yet the opaque script execution and broad action scope make it medium risk.

Confidence: 81%Severity: 57%
Audit Metadata
Analyzed At
Mar 15, 2026, 11:09 AM
Package URL
pkg:socket/skills-sh/HouseGarofalo%2Fclaude-code-base%2Fharness-initializer%2F@622e65ce234b0edbb331f4f97b34098590f914a7
Security Audit — socket — harness-initializer