create-agent
Warn
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: MEDIUMPROMPT_INJECTIONDATA_EXFILTRATIONSAFE
Full Analysis
- [PROMPT_INJECTION]: The skill metadata identifies the author as 'Harness', but the publishing account context provided is 'thisrohangupta'. This discrepancy in authorship is deceptive and could lead to misjudgment of the skill's security profile.
- [PROMPT_INJECTION]: The skill facilitates the creation of agents that ingest untrusted external data (e.g., repository source code, pull request comments) and grants them high-privilege tools such as 'Bash' and GitHub repository modification tools. There are no explicit instructions or delimiters included to prevent these agents from obeying malicious instructions embedded in the analyzed code.
- [DATA_EXFILTRATION]: Example configurations in 'references/agent-examples.md' include a specific, hardcoded ngrok tunnel URL ('harmfully-unregulative-theressa.ngrok-free.dev'). Users following these examples might inadvertently route data through an unmanaged tunnel if they do not provide their own endpoint.
- [SAFE]: Container images are sourced from the official Harness registry ('pkg.harness.io').
- [SAFE]: Authentication for AWS Bedrock and GitHub is handled using standard Harness secret interpolation ('<+secrets.getValue()>'), which prevents the hardcoding of credentials.
Audit Metadata