agent-harness

Warn

Audited by Socket on Sep 24, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/run-shipped-checkpoints.sh

This is an automation wrapper whose intended function is to fetch and execute checkpoint validators. It contains no evident direct malware such as credential theft, exfiltration, persistence, or sabotage. However, it has a significant supply-chain security risk because the default runner comes from the mutable main branch and is executed with bash, while cached repositories are trusted without integrity verification. Runner and checkpoint refs should be immutable and verified by commit or checksum, and checkpoint paths should be constrained within the fetched repository.

Confidence: 97%Severity: 72%
Audit Metadata
Analyzed At
Sep 24, 2026, 05:41 AM
Package URL
pkg:socket/skills-sh/netresearch%2Fagent-harness-skill%2Fagent-harness%2F@417e5dc2c27c4ff15c17931c511a2052cd5c3e5637de049c78f415f7f5ec1bc1
Security Audit — socket — agent-harness