harness-synthesizer

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted data to generate security harnesses, creating a surface for indirect prompt injection.
  • Ingestion points: Target agent frontmatter (fields like tools, domain, and limitations) and previous session logs found in the .codex/outputs/ directory.
  • Boundary markers: No specific delimiters or instructions to ignore embedded malicious content within the processed data are defined in the workflow.
  • Capability inventory: The skill has file system write access to create and modify YAML files in the .codex/outputs/harnesses/ directory.
  • Sanitization: No input validation or sanitization mechanisms are described for the data ingested from agent frontmatter or session logs before it is processed by the LLM.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 10:14 AM
Security Audit — agent-trust-hub — harness-synthesizer