harness-genome
Warn
Audited by Socket on Jun 18, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the stated purpose is coherent for a repo analysis skill, but its execution trust is weak because it relies on an unpinned `npx metaharness` command whose official publisher/distribution path was not verified and appears inconsistent with the project evidence found. No clear credential theft or malicious exfiltration is shown, but supply-chain risk is material.
Confidence: 84%Severity: 68%
Audit Metadata