harness
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill uses
npx @ericrisco/rscto install workspace skills and perform consultations. It also generates scripts that pipe API responses from trusted services (e.g., Stripe, Mailjet, Hetzner, OpenAI) intopython3 -cfor JSON parsing. These behaviors are aligned with the skill's operational purpose and target vendor or well-known service infrastructure. Additionally, the skill references a session hook script.rsc/worklog-checkpoint.mjsto be executed via Node.js. - [COMMAND_EXECUTION]: The skill executes
bash -nto perform syntax validation on newly generated or migrated shell scripts to prevent errors before user execution. - [INDIRECT_PROMPT_INJECTION]: The skill provides an automated knowledge ingestion engine that reads user-supplied files from an
inbox/directory and project documents. This data is processed by the agent to create synthesized wiki articles. - Ingestion points:
02-DOCS/inbox/and workspace-wide document scanning (controlled by.rscignore). - Boundary markers: The
wiki-protocol.mdinstructs the agent to preserve source text and clean only formatting noise in the raw extraction layer. - Capability inventory: The skill can write files, modify project metadata (CLAUDE.md/AGENTS.md), and execute local commands (
bash -n,python3,node). - Sanitization: No specific automated sanitization or filtering of ingested content is detailed beyond structural markdown extraction.
Audit Metadata