harness-check
Warn
Audited by Socket on Sep 10, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s risky actions are largely aligned with its stated purpose of generating comprehensive native telemetry, but it intentionally performs high-impact probes and limits user visibility into the full manual checklist. No explicit third-party credential exfiltration is shown in the provided text, yet the local scripts and generated behaviors create substantial operational risk and warrant careful sandboxing and code review before use.
Confidence: 85%Severity: 71%
Audit Metadata