harness-expert

Warn

Audited by Socket on Feb 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The provided artifact is a descriptive Harness Expert Skill specification detailing template types, inputs, patterns, and examples. There is no runnable payload, no hardcoded secrets, and no autonomous actions beyond templating guidance. The security posture is generally benign, but there are moderate risk indicators related to secret handling in HTTP calls, potential repository access through embedded Git operations, and the need for proper versioning and input validation when deploying templates. Overall, it is a benign design/document piece with some medium-risk considerations around secret exposure and write-access patterns if misused.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 27, 2026, 07:29 PM
Package URL
pkg:socket/skills-sh/lobbi-docs%2Fclaude%2Fharness-expert%2F@534ab5fda9c96b7b00fead0661bc00815f15ece6