harvard-art-museums-data-pipeline

Warn

Audited by Socket on Oct 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The data flows and credential use are broadly consistent with a museum-data ETL skill, and API calls go directly to Harvard’s official endpoint. The main concern is install trust: the skill published by ara.so/aradotso directs users to clone a separate personal GitHub repository, creating a third-party supply-chain hop without clear same-org verification. No credential exfiltration, proxy routing, hidden execution, or malicious payload behavior is evident.

Confidence: 89%Severity: 58%
Audit Metadata
Analyzed At
Oct 1, 2026, 01:37 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Fdata-skills%2Fharvard-art-museums-data-pipeline%2F@f67576993f6ac57b5122a301d63c16e7f7e62afd551b777e958a428b9e1ebc51
Security Audit — socket — harvard-art-museums-data-pipeline