harness-genome

Warn

Audited by Socket on Jun 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose is coherent for a repo analysis skill, but its execution trust is weak because it relies on an unpinned `npx metaharness` command whose official publisher/distribution path was not verified and appears inconsistent with the project evidence found. No clear credential theft or malicious exfiltration is shown, but supply-chain risk is material.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
Jun 18, 2026, 06:40 PM
Package URL
pkg:socket/skills-sh/ruvnet%2Fruflo%2Fharness-genome%2F@b76d03646338bfe0502be5c0458b30dbb7195d8c6282cae81c73241596a52cd9
Security Audit — socket — harness-genome