harvard-artifacts-data-engineering-app

Warn

Audited by Socket on Oct 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s ETL/database/dashboard behavior matches its stated purpose, but the trust chain is inconsistent: ara.so publishes the skill while installation comes from an unrelated personal GitHub repo with limited release provenance. Because that repo would receive database credentials and an API key, the overall risk is medium-high despite otherwise normal data-engineering functionality.

Confidence: 89%Severity: 82%
Audit Metadata
Analyzed At
Oct 1, 2026, 01:37 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Fdata-skills%2Fharvard-artifacts-data-engineering-app%2F@0ceae4e7c5722db5029e5402d9fc3034a4ebf38eb3ee73af18df85cd8587809c
Security Audit — socket — harvard-artifacts-data-engineering-app