harness-initializer
Warn
Audited by Socket on Mar 15, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is mostly aligned with its stated purpose and uses Archon in a coherent way, but it grants broad autonomous setup powers: executing unspecified local init scripts, writing files, updating external project state, and committing all repo contents. No clear malware or credential-harvesting behavior is present, yet the opaque script execution and broad action scope make it medium risk.
Confidence: 81%Severity: 57%
Audit Metadata