autonomous-agent-harness
Warn
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: MEDIUMPERSISTENCEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PERSISTENCE]: The skill is primarily designed to establish long-term persistence by configuring scheduled tasks (crons) and dispatch mechanisms. It instructs the agent to set up recurring sessions for tasks like daily briefings and hourly monitoring using the
mcp__scheduled-tasks__create_scheduled_tasktool. - [INDIRECT_PROMPT_INJECTION]: The autonomous workflows described involve the agent reading untrusted external data and performing actions based on that content, creating a significant attack surface for indirect prompt injection.
- Ingestion points: The skill (in the Examples section of SKILL.md) identifies external sources such as GitHub Pull Requests, search results from Exa, calendar events, and email/Slack threads.
- Boundary markers: The instructions do not include delimiters or specific warnings to prevent the agent from following instructions embedded within the processed external data.
- Capability inventory: The framework enables high-impact capabilities including
computer-use(browser/desktop control), shell command execution viaclaude -p, and broad network operations. - Sanitization: There is no guidance provided for sanitizing or validating external content before it is interpolated into the agent's logic.
- [COMMAND_EXECUTION]: The skill facilitates the execution of shell commands through the programmatic mode of the agent (
claude -p) and documentation of browser automation and desktop control via specific MCP servers. - [EXTERNAL_DOWNLOADS]: The skill recommends configuring MCP servers from the official Anthropic organization (e.g.,
@anthropic/memory-mcp-server,@anthropic/scheduled-tasks-mcp-server). These are established, well-known service providers.
Audit Metadata