harvard-art-museums-data-pipeline
Warn
Audited by Socket on Oct 1, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The data flows and credential use are broadly consistent with a museum-data ETL skill, and API calls go directly to Harvard’s official endpoint. The main concern is install trust: the skill published by ara.so/aradotso directs users to clone a separate personal GitHub repository, creating a third-party supply-chain hop without clear same-org verification. No credential exfiltration, proxy routing, hidden execution, or malicious payload behavior is evident.
Confidence: 89%Severity: 58%
Audit Metadata