view-your-harness

Warn

Audited by Socket on Aug 17, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/serve.py

No direct signs of malicious payloads (e.g., remote C2, credential theft, persistence) are present in this fragment. However, it implements unauthenticated localhost HTTP APIs that can read and return local file contents/images from an allowlisted directory set and can trigger OS open/reveal actions based on network input. If an attacker can reach the listening port or influence requests, the primary risks are local privacy breach/exfiltration and process-intent execution. Supply-chain risk is also partially dependent on the behavior/integrity of the separately executed index.py.

Confidence: 68%Severity: 61%
Audit Metadata
Analyzed At
Aug 17, 2026, 02:57 AM
Package URL
pkg:socket/skills-sh/spacezephyr%2Fbuild-your-harness%2Fview-your-harness%2F@614b20c667e7f214b6f221153789d1b3cbdcd5d5960facce06c5bee30c98a867
Security Audit — socket — view-your-harness