agent-harness
Pass
Audited by Gen Agent Trust Hub on Apr 29, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [SAFE]: The skill uses the allowed-tools capability to restrict the agent's execution environment to a minimal set of required commands, reducing the risk of unintended actions.- [SAFE]: Verification scripts and templates process repository content (such as AGENTS.md) using strict regular expression filters, which effectively mitigates potential command injection risks from untrusted file content.- [EXTERNAL_DOWNLOADS]: Fetches the official actions/checkout GitHub Action within its CI templates, which is pinned to a specific commit hash for integrity.- [SAFE]: The skill facilitates the setup of local automation, such as git hooks, through standard and user-approved mechanisms like direnv, composer, or npm, ensuring transparency and control.
Audit Metadata