imp
Warn
Audited by Socket on Aug 13, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The overall workflow is coherent for implementation orchestration, but the `npx @limchihi/harness state` step introduces a notable supply-chain risk because it can fetch and run an unverified npm package. The rest of the permissions and actions are broadly proportionate to a repo implementation skill, with moderate risk from executing local repo scripts and performing GitHub-side actions.
Confidence: 83%Severity: 74%
Audit Metadata