ns-harness-prepare

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes shell commands using npx @nextstage-brasil/harness. These commands are used to install presets and synchronize architectural rules. As these refer to the author's own verified package infrastructure, this is considered standard functional behavior for a bootstrap tool.
  • [PROMPT_INJECTION]: The instructions direct the agent to skip user confirmation gates (e.g., "proceed immediately into Step 1 — do not wait for user approval") to facilitate an autonomous orchestration workflow. This is a functional design choice for the 'harness prepare' process and does not attempt to override global system safety guidelines or ethical protocols.
  • [DATA_EXPOSURE]: The skill performs read-only scans of application source code to generate architecture and business documentation. There is no evidence of sensitive data (like credentials or environment files) being accessed or exfiltrated to external domains.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 10:39 AM
Security Audit — agent-trust-hub — ns-harness-prepare