autonomous-agent-harness

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s core purpose and capabilities mostly align, but it materially extends trust to external MCP servers, including a beta personal-account Archon stack, and may forward credentials/API keys into those tools. This is not clearly malicious, but the autonomy model, mixed publisher trust, and credential-bearing integrations make it medium risk.

Confidence: 81%Severity: 61%
Audit Metadata
Analyzed At
Mar 15, 2026, 11:09 AM
Package URL
pkg:socket/skills-sh/HouseGarofalo%2Fclaude-code-base%2Fautonomous-agent-harness%2F@f8d5a1bec1d591adb2549984cb0ce2737551a67e