skills/ruvnet/ruflo/harness-learn/Gen Agent Trust Hub

harness-learn

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructions include a command to clone a remote repository from GitHub (https://github.com/ruvnet/metaharness.git). This repository belongs to the skill's author ('ruvnet').
  • [COMMAND_EXECUTION]: The skill executes the metaharness command-line tool using the Bash tool. It passes user-provided parameters such as --host, --model, and --slice to the binary.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from a manifest file provided via the --slice argument.
  • Ingestion points: Data is read from the JSON file path passed to the --slice parameter.
  • Boundary markers: None identified in the skill instructions.
  • Capability inventory: The skill executes the metaharness binary via Bash.
  • Sanitization: No specific sanitization or validation of the manifest content is described in the prompt instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 02:26 PM
Security Audit — agent-trust-hub — harness-learn