ns-harness-architecture-rules
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to run
npx @nextstage-brasil/harness syncto regenerate adapters. This is a standard operation for the toolset provided by the author ('nextstage-brasil'). - [EXTERNAL_DOWNLOADS]: The skill uses
npxto execute a package from the author's official registry namespace (@nextstage-brasil). This is consistent with the skill's stated purpose and originates from the vendor's own infrastructure. - [SAFE]: The reconnaissance phase is explicitly defined as read-only, preventing the agent from modifying application code during the discovery process.
- [SAFE]: Instructions for handling sensitive data include identifying 'secrets locations' as 'forbidden zones' that the agent must not edit.
Audit Metadata