skills/ruvnet/ruflo/harness-score/Gen Agent Trust Hub

harness-score

Warn

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill instructions describe shelling out to npx metaharness score <path> --json. The use of npx triggers the download and execution of packages from the NPM registry during runtime.
  • [COMMAND_EXECUTION]: The skill is configured to use the Bash tool and executes shell commands to run the readiness scorecard. It specifically references a local execution script at scripts/score.mjs and the npx command line.
  • [EXTERNAL_DOWNLOADS]: The skill depends on fetching the metaharness package. While the documentation suggests a pinned range metaharness@~0.3.0, it still relies on external availability and registry trust.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the local file system and processes the output of an external tool.
  • Ingestion points: The <path> argument provided to the skill, which is passed directly to the metaharness command.
  • Boundary markers: The skill does not explicitly define delimiters for the input path or the resulting JSON output from the command.
  • Capability inventory: The skill has Bash access to execute sub-processes and read file system paths.
  • Sanitization: There is no evidence of path sanitization or validation of the JSON structure returned by the external tool before it is processed by the agent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 28, 2026, 02:26 PM
Security Audit — agent-trust-hub — harness-score