lint
Warn
Audited by Socket on Jul 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose is coherent for wiki maintenance, and there is no obvious credential theft or exfiltration path. However, the skill’s trust model is weak because it executes undocumented local/private CLIs from the repo and especially from ~/.claude/harness, which are unverifiable executables with write-side effects on project files. That makes this higher-risk than a normal documentation skill even without confirmed malicious intent.
Confidence: 84%Severity: 72%
Audit Metadata