create-policy
Warn
Audited by Socket on Mar 27, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s capabilities are well aligned with creating Harness governance policies and its data flow appears to stay within Harness, so there is no strong sign of malware or exfiltration. Risk comes from the dependency on Harness MCP v2: official docs exist, but the referenced V2 source provenance appears tied to a personal GitHub account while also receiving Harness API credentials, creating medium supply-chain and credential-forwarding concern.
Confidence: 83%Severity: 64%
Audit Metadata