harvard-artifacts-collection-analytics-pipeline
Warn
Audited by Socket on Oct 1, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s stated ETL/analytics behavior is coherent and its data flows go to official Harvard API endpoints and a user-chosen database, so there is no clear credential harvesting or exfiltration behavior. However, install trust is weakened because the skill publisher and the instructed source repo are unrelated identities, the repo has limited provenance signals, and the dependency set is unpinned with a noted docs/repo inconsistency. This is best classified as medium supply-chain risk, not malicious intent.
Confidence: 89%Severity: 56%
Audit Metadata