harness-setup
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill mentions various commands (e.g.,
$linter-setup,$project-init,$sync-codex) and platform-specific syntax (e.g.,!command). These are used as cross-references to other skills or standard development workflows within the platform's ecosystem and do not represent arbitrary or dangerous shell execution. - [PROMPT_INJECTION]: While the skill contains directive language such as 'Ignore Claude-specific mode-switch instructions' and 'Strict execution contract', these are context-setting instructions for the AI agent to maintain consistency within its specific platform (Codex) rather than malicious attempts to bypass safety filters or exfiltrate data.
- [REMOTE_CODE_EXECUTION]: The skill references external tools like linters (ESLint), mutation testing tools (Stryker, PITest), and CI providers. However, it explicitly states it does not install these tools itself (delegating that to
$linter-setup) and requires user confirmation for tool selection, mitigating risk of unauthorized remote code execution. - [DATA_EXFILTRATION]: There are no patterns detected that attempt to read sensitive files (e.g.,
.ssh,.aws/credentials) or send data to unauthorized external domains. The network operations referenced are for standard development tasks (e.g.,git,gh pr) within a trusted workflow context.
Audit Metadata