harvest

Fail

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: HIGHCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [PERSISTENCE_MECHANISMS]: The skill instructions include a 'Nightly enhance' section suggesting the use of launchd to automate the execution of maintenance and enhancement scripts across sessions.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests session transcripts to propose 'Skill patches' to core configuration files like CLAUDE.md and SKILL.md. \n
  • Ingestion points: Session transcript (SKILL.md) \n
  • Boundary markers: Absent \n
  • Capability inventory: File system writes to SKILL.md and CLAUDE.md, shell script execution via bash (SKILL.md) \n
  • Sanitization: Absent
  • [COMMAND_EXECUTION]: The skill references and executes shell scripts using bash, specifically .claude/lib/install-harness.sh and .cursor/hooks/harvest-stager.sh.
  • [DYNAMIC_EXECUTION]: The skill relies on external shell scripts for core logic such as staging and installation, which are executed at runtime.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 26, 2026, 11:35 AM
Security Audit — agent-trust-hub — harvest