harvest
Fail
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: HIGHCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [PERSISTENCE_MECHANISMS]: The skill instructions include a 'Nightly enhance' section suggesting the use of launchd to automate the execution of maintenance and enhancement scripts across sessions.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests session transcripts to propose 'Skill patches' to core configuration files like CLAUDE.md and SKILL.md. \n
- Ingestion points: Session transcript (SKILL.md) \n
- Boundary markers: Absent \n
- Capability inventory: File system writes to SKILL.md and CLAUDE.md, shell script execution via bash (SKILL.md) \n
- Sanitization: Absent
- [COMMAND_EXECUTION]: The skill references and executes shell scripts using bash, specifically .claude/lib/install-harness.sh and .cursor/hooks/harvest-stager.sh.
- [DYNAMIC_EXECUTION]: The skill relies on external shell scripts for core logic such as staging and installation, which are executed at runtime.
Recommendations
- AI detected serious security threats
Audit Metadata