harness-synthesizer
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted data to generate security harnesses, creating a surface for indirect prompt injection.
- Ingestion points: Target agent frontmatter (fields like
tools,domain, andlimitations) and previous session logs found in the.codex/outputs/directory. - Boundary markers: No specific delimiters or instructions to ignore embedded malicious content within the processed data are defined in the workflow.
- Capability inventory: The skill has file system write access to create and modify YAML files in the
.codex/outputs/harnesses/directory. - Sanitization: No input validation or sanitization mechanisms are described for the data ingested from agent frontmatter or session logs before it is processed by the LLM.
Audit Metadata