harvest

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose broadly matches Harvest management, and the install path is a normal npm package rather than a raw payload, so this is not confirmed malware. However, it requires trusting the Membrane CLI and backend as an intermediary for authentication, credential storage, dynamic action generation, and all Harvest API operations, which creates medium security risk and a data-flow mismatch versus direct official Harvest API use.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Apr 29, 2026, 04:11 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fharvest%2F@5bf77a73e5a74003a171e8c442cdd1008adae62f
Security Audit — socket — harvest