manage-delegates

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides legitimate administrative functionality for Harness Delegates. All operations are scoped to the 'harness-mcp-v2' server and use structured resource management tools.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from the Harness API, which is an external data source.
  • Ingestion points: Delegate health status, version information, and token metadata retrieved via 'harness_list' and 'harness_get' (SKILL.md).
  • Boundary markers: Instructions use explicit tool parameters (resource_type, resource_id) to isolate data.
  • Capability inventory: Includes the ability to create, revoke, and delete delegate tokens via MCP tool calls.
  • Sanitization: The skill relies on the structured nature of the MCP protocol and the backend Harness server to sanitize and validate resource data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 11:24 PM
Security Audit — agent-trust-hub — manage-delegates