harness-engineer-cli

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's main behavior is broadly consistent with project bootstrapping, and referenced vendors appear legitimate, but it introduces unnecessary transitive trust by reading another skill's content from local/session sources and copying it verbatim into the repo. No direct credential harvesting or malicious exfiltration is evident, so this is not confirmed malware; the primary concern is moderate supply-chain and prompt-injection risk from imported skill content.

Confidence: 82%Severity: 56%
Audit Metadata
Analyzed At
Mar 18, 2026, 11:15 PM
Package URL
pkg:socket/skills-sh/phlegonlabs%2Fskills%2Fharness-engineer-cli%2F@55056304940c63cf3eec4917462e6a832c7bef4f