skills/ruvnet/ruflo/harness-mcp-scan/Gen Agent Trust Hub

harness-mcp-scan

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill utilizes the metaharness package (pinned to version ~0.3.0), which serves as a dependency for the scanning functionality.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input from local JSON configuration files (.mcp/servers.json and .harness/claims.json). * Ingestion points: Reads local configuration files to identify security issues. * Boundary markers: The skill is restricted to static analysis and explicitly avoids executing any of the tools it identifies. * Capability inventory: The skill uses Bash and a Node.js script for file reading and processing. * Sanitization: Results are presented in structured formats (JSON or tables) for review.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 02:26 PM
Security Audit — agent-trust-hub — harness-mcp-scan