harness-ceo

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill orchestrates complex tasks by ingesting data from various external sources, creating a potential surface for indirect prompt injection.\n
  • Ingestion points: The agent reads user-provided task descriptions (e.g., in assets/delegation-packet.md), model matrices (assets/model-matrix.md), and knowledge indices (assets/knowledge-map.md) located within the user's workspace.\n
  • Boundary markers: The skill uses structured templates and explicit role manuals (CEO, Commander, Worker) to scope agent behavior, but it does not employ strict cryptographic or non-textual delimiters for ingested external content.\n
  • Capability inventory: The skill interacts with the local environment using the ha CLI tool and Git for workspace management, and processes PR/CI feedback, which represents a significant capability surface if inputs are manipulated.\n
  • Sanitization: The skill includes extensive instructions for "evidence-based" verification and semantic acceptance (described in references/evidence.md and references/acceptance.md) to ensure that outputs are validated against original requests before being integrated.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 02:35 PM
Security Audit — agent-trust-hub — harness-ceo