harness-update

Warn

Audited by Snyk on Jun 10, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 1.00). The skill may clone and execute remote install code at runtime via "git clone -q --depth 1 -b orca git@github.com:rheinmir/setup.git /tmp/llmwiki-tpl && bash /tmp/llmwiki-tpl/harness/scripts/install-harness.sh", so it fetches and runs remote code (git@github.com:rheinmir/setup.git) that directly executes during the skill run.

Issues (1)

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 10, 2026, 09:27 AM
Issues
1
Security Audit — snyk — harness-update