addness

Warn

Audited by Socket on May 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The stated purpose is coherent with project/goal tracking, and there is no clear malicious payload in the skill text. However, the skill’s core functionality depends on opaque external CLIs with no install provenance or release verification in the skill, and those binaries are entrusted with reading and writing remote goal data. Broad pass-through commands and unenforced org-write restrictions further increase risk. Main concern is supply-chain and opaque data/credential handling, not confirmed malware.

Confidence: 84%Severity: 82%
Audit Metadata
Analyzed At
May 1, 2026, 10:38 AM
Package URL
pkg:socket/skills-sh/ShunsukeHayashi%2Flark-harness%2Faddness%2F@9e7795c45c1d5764aa42ed898a6f9eae641607b2