dx-harness
Warn
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill uses the
evalcommand inscripts/verify.shandscripts/time-to-first-commit.shto execute scripts and commands discovered in the repository being audited (e.g.,./bootstrap.sh,npm test). While these operations are performed in a scratch git worktree to provide isolation, they represent the execution of potentially untrusted code found in the repository's file system or manifests. - [INDIRECT_PROMPT_INJECTION]: The skill ingests data from untrusted sources, including git commit history (
git log) and repository configuration files, which are used to generate audit findings and scaffolded code. An attacker could potentially embed malicious instructions in commit messages or repository metadata to influence the agent's behavior during the audit and scaffolding workflow. - Ingestion points:
scripts/audit.shreads git commit history to detect attrition patterns;scripts/discover.shreads repository manifests and scripts. - Boundary markers: The skill requires explicit user confirmation via
AskUserQuestionbefore applying any scaffolded changes to the repository. - Capability inventory: The skill can execute shell commands via
eval, write files via template rendering, and manage git worktrees. - Sanitization: The
safe_expandfunction inscripts/lib/common.shrestricts environment variable expansion and blocks command substitution in configuration strings. Template rendering is performed using a Python script to avoid shell injection during substitution. - [COMMAND_EXECUTION]: The skill performs various shell operations including git worktree management, file system operations, and execution of local development tools such as
jq,git,node, andpython3to automate the DX audit and fix workflow.
Audit Metadata