imp

Warn

Audited by Socket on Aug 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The overall workflow is coherent for implementation orchestration, but the `npx @limchihi/harness state` step introduces a notable supply-chain risk because it can fetch and run an unverified npm package. The rest of the permissions and actions are broadly proportionate to a repo implementation skill, with moderate risk from executing local repo scripts and performing GitHub-side actions.

Confidence: 83%Severity: 74%
Audit Metadata
Analyzed At
Aug 13, 2026, 05:35 PM
Package URL
pkg:socket/skills-sh/limchihi%2Fharness%2Fimp%2F@e2585fc0506e2fa79940502f9ded2bc2eab26def80bb5fe0e70238304f6d334f
Security Audit — socket — imp