harvard-art-museums-data-engineering-analytics
Warn
Audited by Socket on Oct 1, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill's capabilities and credential scope are broadly consistent with ETL/dashboard work, and data flows go to the official Harvard API and a user-chosen database. The main concern is install trust: the publisher points users to clone and run a personal GitHub repo from a different owner with limited provenance, which is disproportionate to the claimed curated skill origin but not enough to show confirmed malicious behavior.
Confidence: 89%Severity: 58%
Audit Metadata