test-harness
Warn
Audited by Socket on Jun 15, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's purpose and capabilities mostly align, and Anthropic CLI installation is official, but it asks the agent to install and execute an unpinned unscoped `vigiles` package whose official publisher relationship was not established from the provided evidence. No clear credential theft or malicious exfiltration is present, but install-trust uncertainty and executable third-party test tooling raise medium risk.
Confidence: 100%Severity: 60%
Audit Metadata