ecl-harness-engineer

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as an engineering tool to bootstrap or audit repository infrastructure specifically for AI agent integration. It promotes best practices such as layer-based architecture enforcement and explicit change management.
  • [COMMAND_EXECUTION]: The skill uses local shell commands for project state analysis (e.g., find, wc, grep, go list) and encourages the use of build tools (e.g., make, npm, cargo). These operations are typical for development environments and are intended for project-local maintenance.
  • [DATA_EXFILTRATION]: No malicious data exfiltration patterns were detected. The skill includes security guidelines that explicitly instruct agents to avoid committing secrets and to use environment variables for sensitive data.
  • [PROMPT_INJECTION]: The instructions and sub-agent prompts are technically focused on architectural analysis and code generation. They do not contain markers or patterns used to bypass safety filters or ignore prior instructions.
  • [EXTERNAL_DOWNLOADS]: All external references involve standard package managers (npm, pip, go mod) or official developer tools. No suspicious remote script execution (e.g., curl | bash from unknown domains) is present.
  • [OBFUSCATION]: There is no evidence of obfuscation. The presence of specific Unicode characters in the encoding linter is a functional feature for detecting text corruption (mojibake) in the target codebase.
  • [DYNAMIC_EXECUTION]: While the skill generates and executes local scripts (Bash, PowerShell, Python), this is the primary intended function for project automation and verification.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 09:51 AM
Security Audit — agent-trust-hub — ecl-harness-engineer