autonomous-agent-harness

Warn

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: MEDIUMPERSISTENCEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PERSISTENCE]: The skill is primarily designed to establish long-term persistence by configuring scheduled tasks (crons) and dispatch mechanisms. It instructs the agent to set up recurring sessions for tasks like daily briefings and hourly monitoring using the mcp__scheduled-tasks__create_scheduled_task tool.
  • [INDIRECT_PROMPT_INJECTION]: The autonomous workflows described involve the agent reading untrusted external data and performing actions based on that content, creating a significant attack surface for indirect prompt injection.
  • Ingestion points: The skill (in the Examples section of SKILL.md) identifies external sources such as GitHub Pull Requests, search results from Exa, calendar events, and email/Slack threads.
  • Boundary markers: The instructions do not include delimiters or specific warnings to prevent the agent from following instructions embedded within the processed external data.
  • Capability inventory: The framework enables high-impact capabilities including computer-use (browser/desktop control), shell command execution via claude -p, and broad network operations.
  • Sanitization: There is no guidance provided for sanitizing or validating external content before it is interpolated into the agent's logic.
  • [COMMAND_EXECUTION]: The skill facilitates the execution of shell commands through the programmatic mode of the agent (claude -p) and documentation of browser automation and desktop control via specific MCP servers.
  • [EXTERNAL_DOWNLOADS]: The skill recommends configuring MCP servers from the official Anthropic organization (e.g., @anthropic/memory-mcp-server, @anthropic/scheduled-tasks-mcp-server). These are established, well-known service providers.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 12, 2026, 03:40 PM
Security Audit — agent-trust-hub — autonomous-agent-harness