harness-synthesizer

Fail

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: HIGHCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides explicit instructions on how to bypass 'sensitive-path' auditing controls. It directs the agent to write sensitive artifacts to temporary directories (/tmp) first and then use a shell script to move them into restricted directories (such as .claude/outputs/), explicitly stating that 'script-internal cp to .claude/ is not audited'.
  • [COMMAND_EXECUTION]: The skill demonstrates and encourages dynamic code execution patterns using subprocess.run to execute Python code constructed at runtime. This includes wrapping inputs in Base64 to bypass lexical filters and executing code within subprocesses with custom environment variables.
  • [DATA_EXFILTRATION]: The workflow requires the agent to read and analyze potentially sensitive session logs and previous tool call patterns located in the .claude/outputs/ directory to facilitate its 'synthesis' logic.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
May 15, 2026, 06:17 PM
Security Audit — agent-trust-hub — harness-synthesizer