harness-update

Warn

Audited by Socket on Jun 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s actions mostly fit its stated migration/update purpose, but it relies on an unpinned GitHub clone-and-execute installer from a low-verifiability repo with no release trail. Data flow stays local except for the GitHub fetch, and requested file changes are proportionate, so this looks more like supply-chain/install-trust risk than confirmed malicious behavior.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 10, 2026, 09:29 AM
Package URL
pkg:socket/skills-sh/rheinmir%2Fsetup%2Fharness-update%2F@9bc4ae136d4524626078639fdcd3974212794865
Security Audit — socket — harness-update