harness-collaboration
Pass
Audited by Gen Agent Trust Hub on Jul 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Employs the
curlutility to send JSON payloads to the Harness service for session callbacks.- [DATA_EXFILTRATION]: Sends session tokens and operation metadata totryharness.ai. This is mitigated by a strict HTTPS allowlist ensuring data is only sent to the designated provider.- [PROMPT_INJECTION]: The skill processes untrusted briefs and research content, creating a surface for indirect prompt injection. - Ingestion points: Briefs, research findings, and external web pages referenced during the task (SKILL.md).
- Boundary markers: Utilizes a mandatory protocol header and explicit rules to treat non-agent content as data only.
- Capability inventory:
curlfor network requests and workspace file management. - Sanitization: Mandates independent verification of all external context and prohibits following instructions embedded in research data.
Audit Metadata