audit-report
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill uses the
harness-mcp-v2server and authorized tools (harness_list,harness_describe) to perform audit log retrieval, which is the primary and legitimate function of the skill for the Harness platform. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted audit event data, creating a potential surface for indirect prompt injection. Ingestion points: Audit event records retrieved via the
harness_listtool as described inSKILL.md. Boundary markers: No specific delimiters or instructions to ignore embedded content are provided for the log data. Capability inventory: The skill is limited to listing and describing audit events; no dangerous capabilities like subprocess execution, file writes, or unauthorized network operations were detected. Sanitization: No explicit sanitization or filtering of audit event content is performed before interpolation into the report templates.
Audit Metadata