create-service

Pass

Audited by Gen Agent Trust Hub on Mar 26, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill instructions describe scanning local codebase files (e.g., k8s manifests, Dockerfiles, serverless.yml) to automatically determine deployment types and artifact sources. This represents a surface for indirect prompt injection.
  • Ingestion points: Local project files and directory structures used in the detection logic in SKILL.md.
  • Boundary markers: The instructions lack delimiters or explicit warnings for the agent to ignore instructions embedded within the analyzed files.
  • Capability inventory: The skill uses the harness_create tool via the harness-mcp-v2 server to create service definitions in the Harness environment.
  • Sanitization: No specific sanitization, validation, or escaping of the values extracted from the project files is mentioned.
  • [PROMPT_INJECTION]: There is an inconsistency between the skill's reported author (thisrohangupta) and the metadata author field (Harness). This metadata mismatch is noted as a potential deception risk.
  • [SAFE]: The skill uses established, specialized MCP tools for resource management on the Harness platform. No hardcoded credentials, unauthorized remote code execution, or persistence mechanisms were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 26, 2026, 10:23 PM
Security Audit — agent-trust-hub — create-service