harness-codebase-reverse-spec
Pass
Audited by Gen Agent Trust Hub on Jul 24, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes a local shell script (scripts/scan_leakage.sh) to identify technical jargon in the generated specification. The script performs local text processing using standard tools and does not interact with the network or access sensitive system files.
- [EXTERNAL_DOWNLOADS]: No remote scripts, external packages, or dependencies are downloaded or executed. All logic and resources are contained within the skill's local files.
- [DATA_EXFILTRATION]: The skill accesses the local codebase for analysis purposes. There are no patterns suggesting unauthorized data transmission, network exfiltration, or hardcoded credentials.
- [PROMPT_INJECTION]: The instructions focus on structured analysis and business logic extraction. No patterns intended to bypass safety guardrails or override system prompts were identified.
Audit Metadata