add

Warn

Audited by Socket on Apr 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core manifest-editing behavior is coherent, but the skill is a transitive skill loader for arbitrary GitHub sources and analyzes untrusted remote SKILL.md content. Main concerns are third-party skill trust and indirect prompt injection, not confirmed malware or direct credential theft.

Confidence: 89%Severity: 68%
Audit Metadata
Analyzed At
Apr 11, 2026, 05:23 AM
Package URL
pkg:socket/skills-sh/myuon%2Fharness%2Fadd%2F@e97539e5869dcd12228009759747017fe61a0e85