harvard-artifacts-collection-analytics-pipeline

Warn

Audited by Socket on Oct 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s stated ETL/analytics behavior is coherent and its data flows go to official Harvard API endpoints and a user-chosen database, so there is no clear credential harvesting or exfiltration behavior. However, install trust is weakened because the skill publisher and the instructed source repo are unrelated identities, the repo has limited provenance signals, and the dependency set is unpinned with a noted docs/repo inconsistency. This is best classified as medium supply-chain risk, not malicious intent.

Confidence: 89%Severity: 56%
Audit Metadata
Analyzed At
Oct 1, 2026, 01:37 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Fdata-skills%2Fharvard-artifacts-collection-analytics-pipeline%2F@2a67110a13a20b74d57915cf56b550bbf6c044507febd588bfca0eebd1fd7f6d
Security Audit — socket — harvard-artifacts-collection-analytics-pipeline