harness-security-bench
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads the
@metaharness/darwinpackage from the npm registry using thenpxcommand. While npm is a well-known service, the package originates from an organization that is not explicitly pre-verified. - [REMOTE_CODE_EXECUTION]: The skill uses
npx -yto execute the@metaharness/darwinpackage. The-yflag bypasses user confirmation for package installation and execution, allowing remote code to run automatically. - [INDIRECT_PROMPT_INJECTION]: The skill processes markdown output from an external tool to generate structured JSON reports, creating a vulnerability surface for instructions embedded in tool output.
- Ingestion points: Output from the
metaharness-darwin security benchcommand execution. - Boundary markers: No explicit delimiters or instructions to ignore embedded content are described in the parsing logic.
- Capability inventory: The skill is granted access to the
Bashtool, enabling shell command execution. - Sanitization: No specific sanitization, validation, or escaping of the tool's markdown output is mentioned before processing.
Audit Metadata