harness-ceo
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill orchestrates complex tasks by ingesting data from various external sources, creating a potential surface for indirect prompt injection.\n
- Ingestion points: The agent reads user-provided task descriptions (e.g., in
assets/delegation-packet.md), model matrices (assets/model-matrix.md), and knowledge indices (assets/knowledge-map.md) located within the user's workspace.\n - Boundary markers: The skill uses structured templates and explicit role manuals (CEO, Commander, Worker) to scope agent behavior, but it does not employ strict cryptographic or non-textual delimiters for ingested external content.\n
- Capability inventory: The skill interacts with the local environment using the
haCLI tool and Git for workspace management, and processes PR/CI feedback, which represents a significant capability surface if inputs are manipulated.\n - Sanitization: The skill includes extensive instructions for "evidence-based" verification and semantic acceptance (described in
references/evidence.mdandreferences/acceptance.md) to ensure that outputs are validated against original requests before being integrated.
Audit Metadata