eval-harness

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill defines a structured framework for evaluation-driven development (EDD) and does not contain any malicious code, obfuscation, or unauthorized access patterns.
  • [COMMAND_EXECUTION]: The skill uses standard tools like Bash, Grep, and npm to perform deterministic code checks (e.g., npm test, npm run build). These are executed locally and are intended for legitimate verification of code changes within a development environment.
  • [PROMPT_INJECTION]: The skill defines a pattern for reading evaluation criteria from local files. While this represents a data ingestion surface, it is a functional requirement for the skill's purpose and does not demonstrate any intent to bypass safety guidelines or override agent behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 03:42 AM
Security Audit — agent-trust-hub — eval-harness