test-harness

Warn

Audited by Socket on Jun 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose and capabilities mostly align, and Anthropic CLI installation is official, but it asks the agent to install and execute an unpinned unscoped `vigiles` package whose official publisher relationship was not established from the provided evidence. No clear credential theft or malicious exfiltration is present, but install-trust uncertainty and executable third-party test tooling raise medium risk.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 15, 2026, 10:29 PM
Package URL
pkg:socket/skills-sh/zernie%2Fvigiles%2Ftest-harness%2F@95b25b1b0b57d524a91b3e1983b66b165307a19cc5e51a80aba74c9c5d015b9a
Security Audit — socket — test-harness