harvard-art-museums-etl-pipeline

Warn

Audited by Socket on Oct 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The ETL/database/dashboard capabilities match the stated purpose and data flows go to official Harvard and local DB endpoints, so there is no clear exfiltration or malicious logic. However, install trust is weakened because the skill published by ara.so tells users to clone and run code from an unrelated personal GitHub repository, plus unpinned dependencies. That mismatch makes the skill risky enough to flag as suspicious rather than benign.

Confidence: 91%Severity: 64%
Audit Metadata
Analyzed At
Oct 1, 2026, 01:37 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Fdata-skills%2Fharvard-art-museums-etl-pipeline%2F@f3266887d9160835b6a35ff2ba07301469ba1c56766d8dfdcace17890590882c
Security Audit — socket — harvard-art-museums-etl-pipeline