harness-update
Warn
Audited by Snyk on Jun 10, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 1.00). The skill may clone and execute remote install code at runtime via "git clone -q --depth 1 -b orca git@github.com:rheinmir/setup.git /tmp/llmwiki-tpl && bash /tmp/llmwiki-tpl/harness/scripts/install-harness.sh", so it fetches and runs remote code (git@github.com:rheinmir/setup.git) that directly executes during the skill run.
Issues (1)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata