harness-security-bench

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads the @metaharness/darwin package from the npm registry using the npx command. While npm is a well-known service, the package originates from an organization that is not explicitly pre-verified.
  • [REMOTE_CODE_EXECUTION]: The skill uses npx -y to execute the @metaharness/darwin package. The -y flag bypasses user confirmation for package installation and execution, allowing remote code to run automatically.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes markdown output from an external tool to generate structured JSON reports, creating a vulnerability surface for instructions embedded in tool output.
  • Ingestion points: Output from the metaharness-darwin security bench command execution.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded content are described in the parsing logic.
  • Capability inventory: The skill is granted access to the Bash tool, enabling shell command execution.
  • Sanitization: No specific sanitization, validation, or escaping of the tool's markdown output is mentioned before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 02:26 PM
Security Audit — agent-trust-hub — harness-security-bench