harness-engineer

Warn

Audited by Socket on May 1, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
skills/harness-onboard/SKILL.md

SUSPICIOUS. The skill's behavior mostly matches its stated onboarding purpose, but it grants a session-starting agent broad autonomous execution over a local repository, including mandatory execution of an unverified repo-local init.sh, file mutation, and commits. No clear exfiltration or credential harvesting is present, so this is not malware, but it is a medium-risk automation skill with notable trust and autonomy concerns.

Confidence: 85%Severity: 64%
SecurityMEDIUM
skills/harness-init/SKILL.md

SUSPICIOUS: the visible scaffold behavior mostly matches the stated harness-init purpose, and no external exfiltration or credential harvesting is shown. However, the undocumented `../../install.sh` and hook payloads create a significant trust gap, and the skill auto-installs dependencies, runs repo scripts, modifies Claude settings, and commits changes without strong verification.

Confidence: 84%Severity: 74%
Audit Metadata
Analyzed At
May 1, 2026, 10:52 PM
Package URL
pkg:socket/skills-sh/lauraflorentin%2Fskills-marketplace%2Fharness-engineer%2F@a2d314d06ae085c2ab2e2050e62b0b5aea16373e