harness-engineer-cli
Warn
Audited by Socket on Mar 18, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill's main behavior is broadly consistent with project bootstrapping, and referenced vendors appear legitimate, but it introduces unnecessary transitive trust by reading another skill's content from local/session sources and copying it verbatim into the repo. No direct credential harvesting or malicious exfiltration is evident, so this is not confirmed malware; the primary concern is moderate supply-chain and prompt-injection risk from imported skill content.
Confidence: 82%Severity: 56%
Audit Metadata