agent-harness

Pass

Audited by Gen Agent Trust Hub on May 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a legitimate development tool for repository auditing and infrastructure management.
  • [COMMAND_EXECUTION]: The verification script (scripts/verify-harness.sh) and assessment checkpoints (checkpoints.yaml) utilize standard shell utilities such as grep, awk, sed, and wc to parse and validate repository artifacts like AGENTS.md, Makefile, and package.json.
  • [EXTERNAL_DOWNLOADS]: The CI workflow templates (templates/harness-verify.yml.tmpl) reference the official actions/checkout GitHub Action using a secure commit hash. No unauthorized or untrusted external downloads or dependencies were identified.
  • [PROMPT_INJECTION]: The skill's instructions and documentation focus on guiding the agent through repository auditing and setup tasks. No attempts to override system prompts or bypass safety guidelines were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
May 20, 2026, 03:29 AM
Security Audit — agent-trust-hub — agent-harness