harness-mcp

Warn

Audited by Socket on Aug 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The purpose largely matches Harness/Jira automation, and primary API data flows are to expected first-party services, but the install path is internally inconsistent: the skill tells users to run an npm package name that does not match Harness's official documented MCP package. Because that external MCP process receives a Harness API key and the skill enables autonomous repo/PR/pipeline/Jira actions, the overall risk is high enough to treat as suspicious rather than benign.

Confidence: 88%Severity: 79%
Audit Metadata
Analyzed At
Aug 13, 2026, 10:17 AM
Package URL
pkg:socket/skills-sh/thelobbi%2Fclaude%2Fharness-mcp%2F@3c783022bf423268fada829602097778d33dfe4b00ab07f8d98c306cd828cc04
Security Audit — socket — harness-mcp