harvest

Warn

Audited by Socket on Apr 6, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose and local file operations are broadly coherent for knowledge consolidation, and the skill text shows no explicit credential capture or external data routing. However, it relies on an unverifiable `ao` CLI with no confirmed official install or release provenance in the provided evidence, which creates a significant supply-chain trust gap.

Confidence: 83%Severity: 72%
Audit Metadata
Analyzed At
Apr 6, 2026, 01:31 PM
Package URL
pkg:socket/skills-sh/boshu2%2Fagentops%2Fharvest%2F@035b1e3770b4c39930a14aade79e5c94e4dd870f