ejentum-reasoning-harness
Warn
Audited by Socket on May 25, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is mostly coherent with its stated purpose and uses a proportionate API key plus a normal npm install path, so it does not look overtly malicious. The main concern is data-flow integrity: prompts and auth are routed to a remote gateway, and the returned scaffold is explicitly fed into the agent's internal reasoning process, creating moderate remote-content and privacy risk.
Confidence: 100%Severity: 60%
Audit Metadata