harvard-artifacts-data-engineering-app
Warn
Audited by Socket on Oct 1, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill’s ETL/database/dashboard behavior matches its stated purpose, but the trust chain is inconsistent: ara.so publishes the skill while installation comes from an unrelated personal GitHub repo with limited release provenance. Because that repo would receive database credentials and an API key, the overall risk is medium-high despite otherwise normal data-engineering functionality.
Confidence: 89%Severity: 82%
Audit Metadata