harness-install

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches source code from the developer's GitHub repository (FairladyZ625/harness-anything).
  • [REMOTE_CODE_EXECUTION]: Clones a remote repository and executes its TypeScript entry point using node to drive installation and task execution.
  • [COMMAND_EXECUTION]: Executes shell commands for project environment inspection and tool initialization, including instructions to modify the execution environment to satisfy review independence logic.
  • [INDIRECT_PROMPT_INJECTION]: Processes instructions from project files (AGENTS.md, CLAUDE.md) to merge harness-specific configurations.
  • Ingestion points: Project-root instruction files (AGENTS.md, CLAUDE.md).
  • Boundary markers: Employs specific section headers and required anchors to delimit merged content.
  • Capability inventory: File system writes, CLI execution, and build command invocation.
  • Sanitization: Requires the agent to show the user a diff of changes for manual review before proceeding.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 02:32 PM
Security Audit — agent-trust-hub — harness-install