harness-sync
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is designed with a limited scope, focusing only on 'instruction surface' files (documentation and agent-specific guidelines) while explicitly refusing to modify critical execution settings like settings.json, hooks, MCP configurations, or CI files.
- [PROMPT_INJECTION]: The skill processes untrusted repository metadata which presents an indirect prompt injection surface.
- Ingestion points: Project manifests including package.json, Makefile, and CI configs (SKILL.md Step 3).
- Boundary markers: Employs 'harness:begin' and 'harness:end' delimiters for its managed content blocks (playbook.md).
- Capability inventory: Possesses filesystem write capabilities for entry files such as CLAUDE.md and AGENTS.md.
- Sanitization: Mitigates risks via a mandatory approval workflow that requires user review of proposed content and diffs before execution (SKILL.md Step 4).
Audit Metadata