harness

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose and commands are internally coherent, and the CLI comes from an official npm package rather than an obviously malicious installer. However, the integration routes authentication, credential refresh, and Harness API traffic through Membrane as a third-party intermediary instead of direct first-party Harness access, which raises medium trust and data-flow risk for sensitive DevOps data.

Confidence: 85%Severity: 59%
Audit Metadata
Analyzed At
Apr 29, 2026, 06:15 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fharness%2F@868012358be12a3bb41ab7c410ca25d6cb00b4c8
Security Audit — socket — harness