krt-harness-wise

Pass

Audited by Gen Agent Trust Hub on May 12, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is strictly limited to planning and documentation tasks, containing an explicit core rule that prohibits writing project application code, tests, migrations, or configurations. This design ensures the skill remains a low-privilege operational helper.\n- [EXTERNAL_DOWNLOADS]: The skill references official prompt engineering and agent instruction documentation from trusted sources, including OpenAI, Anthropic, GitHub, Microsoft, and Google. These URLs are provided as static informational references in the documentation and do not involve executable code or automated software downloads.\n- [SAFE]: The skill's data ingestion process includes mandatory document classification (KEEP, SUMMARIZE, IGNORE, STALE) and anti-bloat rules. These measures serve to filter and sanitize the context extracted from untrusted repository files, effectively reducing the surface area for indirect prompt injection.\n- [COMMAND_EXECUTION]: The skill's primary capability is restricted to writing markdown harness artifacts in user-confirmed paths within the documentation directory (e.g., docs/harnesses/). This activity is well-defined and includes requirements for standardized frontmatter and content structure.
Audit Metadata
Risk Level
SAFE
Analyzed
May 12, 2026, 06:56 AM