everything-claude-code-harness

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's broad harness functionality is mostly consistent with its stated purpose, but provenance is unclear because the claimed publisher, GitHub owner, marketplace package, and custom domain do not cleanly align. It also introduces transitive plugin installation, persistent memory hooks, and broad command/hook control, which make it medium risk even without direct evidence of credential theft or exfiltration.

Confidence: 79%Severity: 66%
Audit Metadata
Analyzed At
Mar 16, 2026, 05:21 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Ftrending-skills%2Feverything-claude-code-harness%2F@f56b1232b51e82011cf0b4f16647da46680329bd