lint

Warn

Audited by Socket on Jul 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is coherent for wiki maintenance, and there is no obvious credential theft or exfiltration path. However, the skill’s trust model is weak because it executes undocumented local/private CLIs from the repo and especially from ~/.claude/harness, which are unverifiable executables with write-side effects on project files. That makes this higher-risk than a normal documentation skill even without confirmed malicious intent.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Jul 18, 2026, 03:09 PM
Package URL
pkg:socket/skills-sh/rheinmir%2Fsetup%2Flint%2F@a0ddee394ddc450bdafd9ed03b0126c394219897
Security Audit — socket — lint