claw-code-harness

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities mostly match its stated purpose and it does not request unusual credentials or route data to third-party APIs, but install trust is weaker than it should be: the skill is published by ara.so while code is sourced from an unlinked instructkr GitHub repo with no releases/package distribution, and it recommends source checkout plus optional dependency install. The official rustup curl|sh step adds low-to-medium supply-chain risk but does not appear malicious on its own.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Mar 31, 2026, 03:34 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Ftrending-skills%2Fclaw-code-harness%2F@67b4620104ea97c6b4c0615c06ac8e283e747c4b