dora-metrics

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill uses a consolidated harness_get and harness_list pattern to interface with an MCP server (harness-mcp-v2). This is a legitimate extension of the agent's capabilities.
  • [SAFE]: The skill is authored by 'Harness' and all referenced resources (MCP server name, metric types, and SEI resource types) are consistent with the vendor's domain and purpose.
  • [SAFE]: No obfuscation, prompt injection, or unauthorized data exfiltration patterns were detected. The instructions focus purely on data retrieval and reporting for engineering metrics.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 11:24 PM
Security Audit — agent-trust-hub — dora-metrics