skills/ericrisco/rsc-harness/harness/Gen Agent Trust Hub

harness

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill uses npx @ericrisco/rsc to install workspace skills and perform consultations. It also generates scripts that pipe API responses from trusted services (e.g., Stripe, Mailjet, Hetzner, OpenAI) into python3 -c for JSON parsing. These behaviors are aligned with the skill's operational purpose and target vendor or well-known service infrastructure. Additionally, the skill references a session hook script .rsc/worklog-checkpoint.mjs to be executed via Node.js.
  • [COMMAND_EXECUTION]: The skill executes bash -n to perform syntax validation on newly generated or migrated shell scripts to prevent errors before user execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides an automated knowledge ingestion engine that reads user-supplied files from an inbox/ directory and project documents. This data is processed by the agent to create synthesized wiki articles.
  • Ingestion points: 02-DOCS/inbox/ and workspace-wide document scanning (controlled by .rscignore).
  • Boundary markers: The wiki-protocol.md instructs the agent to preserve source text and clean only formatting noise in the raw extraction layer.
  • Capability inventory: The skill can write files, modify project metadata (CLAUDE.md/AGENTS.md), and execute local commands (bash -n, python3, node).
  • Sanitization: No specific automated sanitization or filtering of ingested content is detailed beyond structural markdown extraction.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 11:11 PM
Security Audit — agent-trust-hub — harness