migrate-pipeline

Warn

Audited by Gen Agent Trust Hub on Mar 26, 2026

Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The metadata lists 'Harness' as the author, which contradicts the actual author identity of 'thisrohangupta'. This discrepancy is misleading and can result in an incorrect assessment of the skill's official origin and safety.
  • [COMMAND_EXECUTION]: The skill utilizes the 'harness_update' MCP tool to modify live pipeline configurations. While this is the intended purpose, the ability to write changes to cloud resources is a high-privilege operation that requires careful monitoring.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it fetches and processes untrusted pipeline configurations from an external source via the 'harness_get' tool. \n
  • Ingestion points: The skill ingests data from the output of the 'harness_get' tool (the v0 pipeline definition). \n
  • Boundary markers: No boundary markers or instructions are present to ensure the agent ignores malicious content embedded within the fetched pipeline YAML. \n
  • Capability inventory: The skill possesses the 'harness_update' tool which allows it to commit changes back to the production environment. \n
  • Sanitization: No validation or escaping of the external pipeline content is performed before the agent processes the migration transformations.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 26, 2026, 10:23 PM
Security Audit — agent-trust-hub — migrate-pipeline