harness
Warn
Audited by Socket on Apr 22, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s purpose matches Harness integration, and the CLI install path is reasonably legitimate, but the actual data flow is through Membrane as a third-party gateway rather than directly to Harness. That intermediary auth/proxy design is broader and riskier than a direct official API integration, so this is not malware but has meaningful medium security risk.
Confidence: 86%Severity: 58%
Audit Metadata