everything-claude-code-harness
Warn
Audited by Socket on Mar 16, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill's broad harness functionality is mostly consistent with its stated purpose, but provenance is unclear because the claimed publisher, GitHub owner, marketplace package, and custom domain do not cleanly align. It also introduces transitive plugin installation, persistent memory hooks, and broad command/hook control, which make it medium risk even without direct evidence of credential theft or exfiltration.
Confidence: 79%Severity: 66%
Audit Metadata