harness-prd
Pass
Audited by Gen Agent Trust Hub on Jun 14, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Potential for indirect prompt injection (Category 8).
- Ingestion points: The skill ingests the "current conversation context" and reads codebase content during repository exploration to synthesize documentation (SKILL.md).
- Boundary markers: There are no explicit delimiters or instructions provided to the agent to ignore potentially malicious instructions embedded within the ingested context or files.
- Capability inventory: The skill has the capability to write files to the
.harness/directory and publish content to an external issue tracker via project tools (SKILL.md). - Sanitization: The instructions do not specify any validation or sanitization steps for the data extracted from the conversation or codebase before it is used to generate outputs.
Audit Metadata