gan-style-harness
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill implements a multi-agent feedback loop where the Generator agent reads input from specification and feedback files produced by other agents. This creates a surface for indirect prompt injection if those intermediate files were to contain malicious instructions designed to influence the Generator's tool use.
- Ingestion points: The
Generatorrole is instructed to readspec.mdandfeedback-NNN.mdfiles during the implementation phase inSKILL.md. - Boundary markers: The skill relies on natural language role definitions (e.g., "You are a Generator"), but lacks explicit delimiters or instructions to ignore embedded commands within the ingested data files.
- Capability inventory: The agents in this harness are granted access to powerful tools including
Bash,Write,Edit, andPlaywright, which allow for broad file system and network operations. - Sanitization: No sanitization or validation logic is specified for the data files passed between the Planner, Generator, and Evaluator agents.
Audit Metadata