hmharness agent execution layer: base tools, system prompt, sub-agent spawn, and the shared task runner that frontends (cli, web) drive.
At agent runtime, the built-in prompt instructs credential enumeration before user interaction. An unrestricted read tool can return those values, and the agent submits its prompt and tool conversation to a configured chat provider.
Package metadata claims a different repository identity while copied source loads a runtime dependency bridge.
dist/pipeline.jsView on unpkg · L115A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/tools.js#virtual:normalized:round1View on unpkgThe runtime system prompt directs the agent to read every API-key environment variable before asking the user.
dist/prompt.jsView on unpkg · L21The unrestricted read tool accepts absolute paths and returns file content without an approval gate.
dist/tools.jsView on unpkg · L28The runner includes the constructed system prompt in the chat message list alongside the user task.
dist/runner.jsView on unpkg · L311This report applies to @hmharness/agent@0.12.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Package metadata claims a different repository identity while copied source loads a runtime dependency bridge.
dist/pipeline.jsView on unpkg · L115A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/tools.js#virtual:normalized:round1View on unpkgThe runtime system prompt directs the agent to read every API-key environment variable before asking the user.
dist/prompt.jsView on unpkg · L21The unrestricted read tool accepts absolute paths and returns file content without an approval gate.
dist/tools.jsView on unpkg · L28The runner includes the constructed system prompt in the chat message list alongside the user task.
dist/runner.jsView on unpkg · L311