run-pipeline

Warn

Audited by Gen Agent Trust Hub on Mar 31, 2026

Risk Level: MEDIUMPROMPT_INJECTION
Full Analysis
  • [METADATA_POISONING]: The skill's metadata identifies the author as 'Harness', which is inconsistent with the submitter 'thisrohangupta'. This discrepancy is deceptive and could lead users to incorrectly assume the skill is an official integration provided by Harness.
  • [INDIRECT_PROMPT_INJECTION]: The skill interacts with the Harness platform to fetch pipeline and execution data, which represents an indirect prompt injection attack surface.
  • Ingestion points: External data is ingested through the 'harness_search', 'harness_list', and 'harness_get' MCP tools in SKILL.md.
  • Boundary markers: The instructions do not define delimiters or markers to isolate external content from agent instructions, though they include a safety confirmation step for production environments.
  • Capability inventory: The skill has high-impact capabilities, including the ability to trigger, retry, and interrupt pipeline executions via the 'harness_execute' tool.
  • Sanitization: No specific mechanisms for sanitizing or validating the data returned from the Harness environment are described.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 31, 2026, 09:49 PM
Security Audit — agent-trust-hub — run-pipeline