two-agent-harness

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The described two-agent harness is functionally coherent and appears intended to automate local project breakdown and implementation workflows. The primary security concern is installing and auto-executing opaque shell hooks and trusting an installer script without review. The documented bypass keywords meaningfully weaken enforcement. No explicit evidence of network exfiltration or hard-coded credentials is present in the provided description, but the missing script contents create a supply-chain risk. Advise manual code review of the setup script and each hook before installation; treat the package as potentially risky until verified.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 16, 2026, 03:06 AM
Package URL
pkg:socket/skills-sh/ingpoc%2Fskills%2Ftwo-agent-harness%2F@f4504546f89b6fdf82fb83a8969ce049e9b942b0