agent-harness
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a collection of educational documentation and auditing tools designed to improve the reliability and security of agent implementations.
- [COMMAND_EXECUTION]: The script
scripts/audit_agent.pyis a local auditing tool. It scans directories for agent-related code and identifies potential implementation flaws (like unbounded loops or swallowed errors) using static analysis. It does not execute the analyzed files, requires no external dependencies, and performs no network operations. - [CREDENTIALS_UNSAFE]: The documentation discusses credential management and session persistence. It includes dummy placeholders (e.g., 'sk-key') for demonstration purposes and correctly guides users toward secure practices such as using environment variables or system keychains rather than hardcoding secrets.
- [INDIRECT_PROMPT_INJECTION]: The skill addresses indirect prompt injection as a threat vector to be audited. While the scanner script reads external files, it lacks the necessary capabilities (such as network access or file-writing) to be exploited via the content it processes.
- [REMOTE_CODE_EXECUTION]: Documentation for the 'Pi' harness mentions external packages and SDKs (e.g.,
@earendil-works/pi-coding-agent). These are referenced as part of an external framework and are not automatically installed or executed by this skill.
Audit Metadata