qm-harness-snippets
What this skill does
The skill is a tool for interacting with a company's centralized knowledge brain, allowing agents to search and write durable knowledge. It includes setup and provisioning scripts for configuring acce
github/garrytan - Privilege Escalation - 28.2k stars
Threat analysis
Skill info
pkg:github/garrytan/gbrain@75fae74?skill=qm-harness-snippetsAssessments (1)
Privilege Escalation
Privilege Escalation via local-llm-review
provision-scopes.sh
The script provisions OAuth clients for employees and channels, which could be misused if not properly secured. It also writes client secrets to a file (`--secrets-out`), which could be a risk if the Badge
Add the Anomity scan badge for qm-harness-snippets to your README.
How Anomity governs this at runtime
Scan-time vetting tells you what a skill says it will do. Anomity's Endpoint Sensor sees what agents actually do: it discovers skills alongside every other AI artifact on the endpoint, and runtime governance can allow, deny, or log the tool calls a skill triggers. Policy violations route to your SIEM, Slack, email, or Jira, backed by a queryable 90-day audit trail.
Book a 30-minute demo to see your own skill inventory.
Methodology and disputes
Every skill is assessed by the Anomity Skill Intelligence engine against its public source; findings indicate risk patterns, not confirmed exploitation. Maintainer of qm-harness-snippets? Report an issue or request a rescan.




