harness-score
Warn
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: MEDIUMREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill instructions describe shelling out to
npx metaharness score <path> --json. The use ofnpxtriggers the download and execution of packages from the NPM registry during runtime. - [COMMAND_EXECUTION]: The skill is configured to use the
Bashtool and executes shell commands to run the readiness scorecard. It specifically references a local execution script atscripts/score.mjsand thenpxcommand line. - [EXTERNAL_DOWNLOADS]: The skill depends on fetching the
metaharnesspackage. While the documentation suggests a pinned rangemetaharness@~0.3.0, it still relies on external availability and registry trust. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the local file system and processes the output of an external tool.
- Ingestion points: The
<path>argument provided to the skill, which is passed directly to themetaharnesscommand. - Boundary markers: The skill does not explicitly define delimiters for the input path or the resulting JSON output from the command.
- Capability inventory: The skill has
Bashaccess to execute sub-processes and read file system paths. - Sanitization: There is no evidence of path sanitization or validation of the JSON structure returned by the external tool before it is processed by the agent.
Audit Metadata