harvard-artifacts-data-pipeline

Warn

Audited by Socket on Oct 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s stated purpose, credentials, and data flows are mostly consistent with a Harvard API ETL dashboard, and it routes data directly to official Harvard and user-specified database endpoints. The main concern is install trust: the skill published by ara.so points users to clone and run code from an unrelated personal GitHub repository with no same-org verification, plus unpinned Python dependencies. This makes the skill medium risk but not clearly malicious.

Confidence: 92%Severity: 58%
Audit Metadata
Analyzed At
Oct 1, 2026, 01:37 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Fdata-skills%2Fharvard-artifacts-data-pipeline%2F@707f3bc87b3fce5b706e95dc961693c58b1e1e9ff7d81af169a7ebb411b52c7b
Security Audit — socket — harvard-artifacts-data-pipeline