dayu-harness

Warn

Audited by Socket on Jun 2, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/scaffold.sh

No direct evidence of overt malware (no hardcoded secrets, no obvious external exfiltration endpoints, no reverse shells). The primary security risk is supply-chain execution: installer scripts are dynamically selected from manifest-provided .installer.script and executed from the local scripts directory, and the harness also performs authenticated GitHub issue/PR and branch automation. Security therefore hinges on integrity controls for manifests/scripts and strict least-privilege for the gh session; missing implementations for collect_* and helper escaping/writes prevent a fully definitive assessment of path traversal or JSON-handling correctness in this module.

Confidence: 60%Severity: 62%
Audit Metadata
Analyzed At
Jun 2, 2026, 07:40 AM
Package URL
pkg:socket/skills-sh/kinoward%2Fdayu-harness-skill%2Fdayu-harness%2F@e2ed501c5a5f6c268b4665dc3bd04a90b328d9a8
Security Audit — socket — dayu-harness