gan-style-harness

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill implements a multi-agent feedback loop where the Generator agent reads input from specification and feedback files produced by other agents. This creates a surface for indirect prompt injection if those intermediate files were to contain malicious instructions designed to influence the Generator's tool use.
  • Ingestion points: The Generator role is instructed to read spec.md and feedback-NNN.md files during the implementation phase in SKILL.md.
  • Boundary markers: The skill relies on natural language role definitions (e.g., "You are a Generator"), but lacks explicit delimiters or instructions to ignore embedded commands within the ingested data files.
  • Capability inventory: The agents in this harness are granted access to powerful tools including Bash, Write, Edit, and Playwright, which allow for broad file system and network operations.
  • Sanitization: No sanitization or validation logic is specified for the data files passed between the Planner, Generator, and Evaluator agents.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:40 PM
Security Audit — agent-trust-hub — gan-style-harness