harness-prd

Pass

Audited by Gen Agent Trust Hub on Jun 14, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Potential for indirect prompt injection (Category 8).
  • Ingestion points: The skill ingests the "current conversation context" and reads codebase content during repository exploration to synthesize documentation (SKILL.md).
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to ignore potentially malicious instructions embedded within the ingested context or files.
  • Capability inventory: The skill has the capability to write files to the .harness/ directory and publish content to an external issue tracker via project tools (SKILL.md).
  • Sanitization: The instructions do not specify any validation or sanitization steps for the data extracted from the conversation or codebase before it is used to generate outputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 14, 2026, 10:13 PM
Security Audit — agent-trust-hub — harness-prd