skills/affaan-m/ecc/gan-style-harness/Gen Agent Trust Hub

gan-style-harness

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns detected. The skill outlines a sophisticated architectural pattern for autonomous development using standard tools like Bash, file operations, and browser automation via Playwright.
  • [INDIRECT_PROMPT_INJECTION]: The skill inherently possesses an attack surface for indirect prompt injection as it involves agents reading generated specifications, feedback files, and interacting with live web applications. However, this is consistent with the primary purpose of an autonomous development harness.
  • Ingestion points: The Evaluator agent ingests data from a live running application (via Playwright) and from project-specific files (spec.md, feedback.md).
  • Boundary markers: The provided prompt templates do not include explicit boundary markers or 'ignore' instructions for embedded data.
  • Capability inventory: The agents have access to Bash, file system modification (Write/Edit), and browser interaction tools.
  • Sanitization: No explicit sanitization or validation of the ingested external content is mentioned, relying on the underlying model's safety guardrails.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 02:47 PM
Security Audit — agent-trust-hub — gan-style-harness