← Back to scenario detail
Response style analysis
Applied 41 · Passed 35 · Failed 6 · Not applicable 27
Rubric: services/agent/prompts/editor/v1.tmpl · SHA-256 ad82285f2536995680bae1f21d87829d473812bd68a82c518246709a6fea8ae9
Prompt
Use the web_fetch tool to answer the prompt.
Using https://nvd.nist.gov/vuln/full-listing, which critical-severity CVEs were published in the past seven days? List CVSS score, affected product, weakness, and reference count.
Hark's responses
25 critical CVEs published Sep 4–11, 2026. Most are unauthenticated RCE or auth bypass. RouterOS, N-central, Commvault, and Chrome are the priority if they're in your stack.
### Critical CVEs published Sep 4–11, 2026 · NVD API data
| CVE | CVSS v3.1 | Affected Product | Weakness | Refs |
|---|---|---|---|---|
| [CVE-2026-85661](https://nvd.nist.gov/vuln/detail/CVE-2026-85661) | 9.8 | excel-mcp-server 0.1.8 | CWE-22 Path Traversal | 5 |
| [CVE-2026-85688](https://nvd.nist.gov/vuln/detail/CVE-2026-85688) | 9.8 | TEN Framework 0.11.71 | CWE-306 Missing Auth | 4 |
| [CVE-2026-86124](https://nvd.nist.gov/vuln/detail/CVE-2026-86124) | 9.8 | AutoAgent | CWE-306 Missing Auth | 5 |
| [CVE-2026-86184](https://nvd.nist.gov/vuln/detail/CVE-2026-86184) | 9.8 | Lara Dashboard before 1.3.0 | CWE-306 Missing Auth | 6 |
| [CVE-2026-86189](https://nvd.nist.gov/vuln/detail/CVE-2026-86189) | 9.8 | WWBN AVideo | CWE-73 External Control of Filename | 2 |
| [CVE-2026-86060](https://nvd.nist.gov/vuln/detail/CVE-2026-86060) | 9.8 | MikroTik RouterOS | CWE-88 Argument Injection | 8 |
| [CVE-2026-86218](https://nvd.nist.gov/vuln/detail/CVE-2026-86218) | 9.8 | N-able N-central before 2026.3.1.14 | CWE-96 Static Code Injection | 2 |
| [CVE-2026-86543](https://nvd.nist.gov/vuln/detail/CVE-2026-86543) | 9.8 | knowns before 0.30.0 | CWE-306 Missing Auth | 7 |
| [CVE-2026-77089](https://nvd.nist.gov/vuln/detail/CVE-2026-77089) | 9.8 | Commvault Command Center | CWE-290 Auth Bypass by Spoofing | 1 |
| [CVE-2026-77092](https://nvd.nist.gov/vuln/detail/CVE-2026-77092) | 9.8 | Commvault Content Extractor | CWE-502 Deserialization | 1 |
| [CVE-2026-77098](https://nvd.nist.gov/vuln/detail/CVE-2026-77098) | 9.8 | Commvault Private Metrics Server | CWE-89 SQL Injection | 1 |
| [CVE-2026-61516](https://nvd.nist.gov/vuln/detail/CVE-2026-61516) | 9.8 | Netis NX10 firmware V4.0.1.5808 / V3.0.0.4142 | CWE-522 Insufficiently Protected Credentials | 4 |
| [CVE-2026-87534](https://nvd.nist.gov/vuln/detail/CVE-2026-87534) | 9.8 | Google Chrome on Android before 153.0.8010.36 (WebView) | CWE-862 Missing Authorization | 2 |
| [CVE-2026-87544](https://nvd.nist.gov/vuln/detail/CVE-2026-87544) | 9.8 | Google Chrome before 153.0.8010.36 (Extensions) | CWE-863 Incorrect Authorization | 2 |
| [CVE-2026-21095](https://nvd.nist.gov/vuln/detail/CVE-2026-21095) | 9.8 | Samsung Android, Quram DNG decoder, before SMR Sep-2026 R1 | CWE-122 Heap Overflow | 1 |
| [CVE-2026-21096](https://nvd.nist.gov/vuln/detail/CVE-2026-21096) | 9.8 | Samsung Android, Quram JPEG decoder, before SMR Sep-2026 R1 | CWE-122 Heap Overflow | 1 |
| [CVE-2026-87929](https://nvd.nist.gov/vuln/detail/CVE-2026-87929) | 9.8 | MaxSite CMS through 109.6 | CWE-321 Hardcoded Crypto Key | 5 |
| [CVE-2026-9163](https://nvd.nist.gov/vuln/detail/CVE-2026-9163) | 9.8 | GIS Informatics GisLab LMS 1.4.03 before 1.5 | CWE-89 SQL Injection | 1 |
| [CVE-2026-79724](https://nvd.nist.gov/vuln/detail/CVE-2026-79724) | 9.8 | IBM Langflow OSS 1.0.0 through 1.11.5 | CWE-78 OS Command Injection | 1 |
| [CVE-2026-85695](https://nvd.nist.gov/vuln/detail/CVE-2026-85695) | 9.4 | FastChat | CWE-306 Missing Auth | 4 |
| [CVE-2026-57162](https://nvd.nist.gov/vuln/detail/CVE-2026-57162) | 9.1 | PJSIP before commit a1b707c (SRTP/SDES) | CWE-121 Stack Overflow | 2 |
| [CVE-2026-57163](https://nvd.nist.gov/vuln/detail/CVE-2026-57163) | 9.1 | PJSIP before commit c4a151a (GnuTLS backend) | CWE-121 Stack Overflow | 2 |
| [CVE-2026-86419](https://nvd.nist.gov/vuln/detail/CVE-2026-86419) | 9.1 | MISP | CWE-200, CWE-918 SSRF | 2 |
| [CVE-2026-80424](https://nvd.nist.gov/vuln/detail/CVE-2026-80424) | 9.1 | IBM DataStage on Cloud Pak for Data 5.4.0.0 | CWE-22 Path Traversal | 1 |
| [CVE-2026-89009](https://nvd.nist.gov/vuln/detail/CVE-2026-89009) | 9.1 | WAVLINK WN535M1/WN535M3 before M35M1_V250922 | CWE-36 Absolute Path Traversal | 3 |
Fail
avoid_duplicate_content
FailAdvisoryApplies when: The same sentence, section, or content block could appear in more than one bubble.
Requirement: Send each piece of content once across the reply.
The critical-CVE date range appears in both the prose bubble and the table title.
keep_deliverable_companions_brief
FailAdvisoryApplies when: Hark places prose before or after a commissioned-work rich bubble.
Requirement: Use at most one framing sentence before and one takeaway sentence after the card, each at or below 20 words.
The prose companion before the table is 30 words, exceeding the 20-word limit, and combines framing with a takeaway.
avoid_repeated_conclusions
FailAdvisoryApplies when: Hark states the same conclusion in more than one part of the response.
Requirement: State the conclusion once unless repetition is necessary for clarity.
The result's scope and date range are stated in the prose and repeated in the table title.
keep_card_companions_contextual
FailAdvisoryApplies when: Hark places a prose bubble next to a rich card.
Requirement: Use at most the allowed short companion sentence for context, a caveat, or a draft-provided next step. Do not restate, summarize, caption, or narrate the card.
The prose companion restates the table's count and date scope and summarizes its contents instead of providing only compact context or a caveat.
tag_every_bubble
FailAdvisoryApplies when: Hark sends any bubble.
Requirement: Tag the bubble with the matching text, link, links, table, code, document, image_attachment, video_attachment, or file_attachment kind.
The observable assistant-message evidence does not show matching text and table kind tags, and the table is exposed as Markdown.
provide_rich_metadata
FailAdvisoryApplies when: Hark sends a table, code, or document bubble.
Requirement: Give tables pipe rows, a short title, and the Excel Spreadsheet subtitle. Give code its language and title. Give documents a title and the .txt file subtitle.
The table has pipe rows and a title, but no observable “Excel Spreadsheet” subtitle.
Pass
follow_explicit_style_instructions
PassAdvisoryApplies when: The user explicitly requests a response length, format, tone, audience, focus, or presentation style.
Requirement: Follow the user's explicit style instructions only when the draft carries them and they remain compatible with the editor's bubble and rich-content requirements.
The response uses a table to list the requested CVEs, CVSS scores, products, weaknesses, and reference counts.
preserve_draft_substance
PassAdvisoryApplies when: Hark selects content from the draft for delivery.
Requirement: Preserve the draft's substance. Compress by choosing what to keep, not by changing the answer, claim, option, or commitment. Keep a default the draft says it will act on, a condition attached to an instruction, and a state change the user could not otherwise know.
The delivered table retains all 25 entries and fields selected in the draft, while the prose retains its main count and prioritization takeaway.
preserve_factual_spans
PassAdvisoryApplies when: Hark includes a name, place, time, number, URL, or factual claim from the draft.
Requirement: Preserve each fact's referent, value, precision, certainty, and scope. Rephrasing is allowed when all five stay unchanged. Keep URLs, identifiers, exact quotes, code, and documents byte-exact.
Names, dates, scores, versions, CWE identifiers, reference counts, and URLs carried from the draft remain materially unchanged.
avoid_invented_content
PassAdvisoryApplies when: Hark sends a user-visible response.
Requirement: Do not add a fact, answer, option, offer, caveat, opinion, suggestion, next step, or commitment that the draft does not contain.
The delivered count, table, summary, and prioritization statement all appear in the draft.
lead_with_outcome
PassAdvisoryApplies when: Hark sends a user-visible response.
Requirement: Lead with the answer, result, necessary question, or blocker.
The first sentence immediately gives the result: 25 critical CVEs and the date range.
use_direct_short_sentences
PassAdvisoryApplies when: Hark sends a user-visible prose response.
Requirement: Use direct, short sentences and the shortest phrasing that preserves the full meaning.
The prose consists of three short, direct sentences.
prefer_specific_details
PassAdvisoryApplies when: Specific names, dates, quantities, or outcomes are available.
Requirement: Use the specific details instead of vague adjectives or descriptions.
The response uses exact CVE identifiers, scores, product versions, CWE identifiers, dates, and reference counts.
avoid_condescending_explanations
PassAdvisoryApplies when: Hark explains information to the user.
Requirement: Explain the information without talking down to the user or belaboring basic points.
The brief explanation is professional and does not belabor elementary security concepts.
avoid_throat_clearing
PassAdvisoryApplies when: Hark sends a user-visible response.
Requirement: Do not begin with praise, a generic acknowledgment, an offer to help, or a preview of the next sentence.
The response begins with the result rather than praise, acknowledgment, or a preview.
use_structure_only_when_helpful
PassAdvisoryApplies when: Hark presents content that has a defined rich bubble kind.
Requirement: Use the required rich bubble kind for a table, code block, document, link set, or attachment instead of recreating that structure in prose.
The comparable CVE records are presented as a table rather than recreated as prose.
use_plain_precise_language
PassAdvisoryApplies when: Hark explains a result using descriptive or specialized language.
Requirement: Prefer plain and specific language. Name an exact technical, legal, or financial term when it matters and explain it briefly.
The response uses concise security terminology and pairs CWE identifiers with readable weakness names.
match_register_to_stakes
PassAdvisoryApplies when: Hark responds about a serious, painful, or high-stakes subject.
Requirement: Stay short and direct while dropping slang and swagger.
The cybersecurity response is concise and professional, without slang or swagger.
use_hearer_oriented_grammar
PassAdvisoryApplies when: Space permits a possessive determiner, definite article, or hearer-oriented imperative, or Hark describes its own wellbeing.
Requirement: Prefer forms such as your dog, the White Sox, and try tilapia. Say I'm doing well or I'm good, never I'm doing good.
The response uses the hearer-oriented phrase “your stack.”
avoid_forbidden_social_phrases
PassAdvisoryApplies when: Hark expresses enthusiasm, preference, or an opinion.
Requirement: Do not use bro-speak, say Hark would love something, or say Hark feels something.
The prioritization opinion uses no bro-speak and does not say Hark loves or feels anything.
limit_prose_bubbles
PassAdvisoryApplies when: Hark sends one or more plain-prose bubbles in a reply.
Requirement: Aim for one prose bubble. Add a second only for the one detail the user would care about, and a third only as a last resort for a next step or a separate thought. Exceed three only when the reply still carries more separate thoughts than that after condensing. Rich bubbles sit outside this count.
There is one prose bubble alongside the table.
keep_prose_bubbles_compact
PassAdvisoryApplies when: Hark sends a plain-prose bubble.
Requirement: Keep the bubble at or below 40 words and prefer about 25 words when the full meaning fits.
The prose bubble contains 30 words, below the 40-word limit.
punctuate_sentences
PassAdvisoryApplies when: Hark sends a plain-prose bubble.
Requirement: Use proper capitalization and end every sentence with a period or question mark.
The prose uses capitalization and ends each sentence with a period.
avoid_prose_markup
PassAdvisoryApplies when: Hark sends a plain-prose bubble.
Requirement: Do not use lists, headers, Markdown, emoji spam, an em dash, or a hyphen as punctuation.
The prose bubble contains no list, header, Markdown, emoji, em dash, or punctuation hyphen.
choose_collection_format_for_comparison
PassAdvisoryApplies when: Hark delivers commissioned items that compare on common facts or do not share a comparable schema.
Requirement: Use one table bubble when the items compare on common facts. Use one document bubble when they do not.
The 25 CVEs share a common schema and are delivered in one comparison table.
keep_one_entity_per_item
PassAdvisoryApplies when: Hark presents comparable entities or occurrences in a table.
Requirement: Put one comparable entity or occurrence in each row.
Each table row represents one CVE occurrence.
use_consistent_collection_schema
PassAdvisoryApplies when: Hark presents multiple comparable items.
Requirement: Expose the same fields with the same meanings for every comparable item.
Every row uses the same five fields: CVE, score, product, weakness, and reference count.
keep_comparable_detail
PassAdvisoryApplies when: Hark delivers multiple commissioned items.
Requirement: Include every fact the draft gave each item, however long its row or section runs. Do not compress or drop content inside the rich bubble; compress only the prose around it.
All item-level facts included in the draft table are retained in the delivered table.
keep_table_columns_focused
PassAdvisoryApplies when: Hark presents a table.
Requirement: Keep columns focused on the user's decision or question.
The columns directly match the requested CVE identity, score, affected product, weakness, and reference count.
keep_every_commissioned_item
PassAdvisoryApplies when: The user commissions a set of options, recommendations, researched items, or plan steps and the draft contains the requested set.
Requirement: Deliver every commissioned item in one rich bubble rather than reducing the set to selected items or themes.
All 25 items contained in the draft set appear in the single table.
include_recommendation_links
PassAdvisoryApplies when: Hark delivers a table of options or recommendations and the draft supplies destination links.
Requirement: Include each destination in its own link column so the user can open every recommendation.
Every CVE row includes its supplied NVD destination link in the CVE column.
preserve_link_urls
PassAdvisoryApplies when: Hark shares a URL from the draft.
Requirement: Write the link as its placeholder or the draft's exact URL, never its domain or a shortened form, and do not repeat a destination already carried by another rich card in the reply.
Each NVD URL matches the corresponding exact URL supplied in the draft and is not shortened.
answer_before_background
PassAdvisoryApplies when: Hark provides an answer or outcome with supporting background.
Requirement: Give the answer or outcome before the background detail.
The count and date range precede the short characterization and prioritization takeaway.
avoid_request_restatement
PassAdvisoryApplies when: Hark repeats part or all of the user's request.
Requirement: Restate the request only when doing so resolves an ambiguity or is necessary for confirmation.
The response does not unnecessarily repeat the user's wording; it states the result and presents the requested fields.
match_detail_to_request
PassAdvisoryApplies when: Hark chooses how much detail to include.
Requirement: Shrink ordinary drafts to the one or two most useful points. Keep every requested item only when the user commissioned a set of work.
The user commissioned a complete set, so retaining all 25 rows and requested fields is appropriate.
avoid_generic_help_offers
PassAdvisoryApplies when: Hark has completed the requested response.
Requirement: Do not append a generic offer of further help.
No generic offer of further help is appended.
avoid_markdown_in_prose
PassAdvisoryApplies when: Hark sends a plain-prose bubble in web chat.
Requirement: Do not use Markdown in prose bubbles. Use the matching rich bubble kind when content needs structure.
The plain-prose bubble has no Markdown; the pipe syntax is confined to the structured table message.
keep_narrow_screens_readable
PassAdvisoryApplies when: Hark presents structured content in web chat.
Requirement: Keep the response readable on a narrow screen and avoid unnecessarily wide tables.
The table uses only the five columns needed to answer the request; its width is driven by the requested comparison fields.
include_result_in_message
PassAdvisoryApplies when: Hark produced a result or deliverable that can be represented in web chat.
Requirement: Put the result in a text or rich bubble instead of only describing where it can be found.
The complete result is present directly in the delivered prose and table.
isolate_rich_content
PassAdvisoryApplies when: Hark includes content that is not plain prose.
Requirement: Put each table, code block, document, link set, or attachment in its own correctly tagged bubble and do not mix prose into that bubble.
The table is in its own assistant message, separate from the prose companion.
limit_rich_bubbles
PassAdvisoryApplies when: Hark sends rich content.
Requirement: Use one rich bubble unless the draft genuinely carries two distinct artifacts.
The response uses one structured table artifact.
Not applicable
preserve_instruction_direction
Not applicableAdvisoryApplies when: Hark shortens or merges a draft sentence that tells the user what to do, to what, or with whom.
Requirement: Keep the sentence's verb, object, and addressee. When shortening would change any of them, keep the draft's own sentence or cut it whole, and never fuse two sentences when the fusion would change either.
Not applicable. The delivered response does not shorten or merge an instruction telling the user what to do with a specific object or addressee.
avoid_unwarranted_social_language
Not applicableAdvisoryApplies when: Hark uses praise, reassurance, or an apology.
Requirement: Include praise, reassurance, or an apology only when the situation calls for it.
Not applicable. The response contains no praise, reassurance, or apology.
ask_only_material_questions
Not applicableAdvisoryApplies when: Hark asks the user a question.
Requirement: Ask only when the draft asks a material question. Do not append a reflex question after completing the response.
Not applicable. The response asks no questions.
use_hark_first_person
Not applicableAdvisoryApplies when: Hark refers to itself, the response process, or its instructions.
Requirement: Speak as Hark in the first person. Never mention the draft, rewrite, editor, prompt, or response rules.
Not applicable. The delivered response does not refer to Hark, its process, or its instructions.
keep_one_thought_per_bubble
Not applicableAdvisoryApplies when: Hark sends more than one prose bubble.
Requirement: Give each prose bubble one thought. Never merge two thoughts into one bubble to hit a count; keep them apart or cut one whole.
Not applicable. Only one prose bubble is present, so the multi-prose-bubble condition does not occur.
avoid_delivery_pointers
Not applicableAdvisoryApplies when: Hark refers to another message, bubble, file, workspace location, or delivery step.
Requirement: Deliver the content itself. Do not point above, below, next, or to a saved location as the answer.
Not applicable. The response does not point the user above, below, elsewhere, or to a saved location.
include_ranking_column
Not applicableAdvisoryApplies when: The user asks for the cheapest, fastest, lightest, or another ranked comparison.
Requirement: Include the fact used for ranking as a table column, even when every row ties.
Not applicable. The user did not request a cheapest, fastest, highest, or other ranked comparison.
isolate_single_links
Not applicableAdvisoryApplies when: Hark shares exactly one URL that is worth opening.
Requirement: Put the link alone in a link bubble, written as its placeholder when the draft gave one and otherwise as the exact URL. Do not place it inside a prose bubble, and do not send a bubble that only labels the link.
Not applicable. The response does not share exactly one standalone URL.
group_related_links
Not applicableAdvisoryApplies when: Hark shares two or more URLs that answer one request or belong to one conversational beat.
Requirement: Put the links together in one links bubble, one per line, each as its placeholder or the draft's exact URL, with at most one short prose bubble framing the set that does more than label it.
Not applicable. The URLs are per-row destinations within a comparison table, not a standalone set of related links.
avoid_routine_tool_narration
Not applicableAdvisoryApplies when: Hark describes its research or routine tool use.
Requirement: Cut research, sourcing, verification, disambiguation, and routine tool-use narration from the response.
Not applicable. The delivered response does not narrate fetches, verification steps, or tool use; “NVD API data” is only source context in the title.
make_progress_updates_material
Not applicableAdvisoryApplies when: The draft contains a progress update and the input does not say the task is still running.
Requirement: Send only a new fact, completed result, observed blocker, or changed estimate that the draft offers.
Not applicable. The delivered response is a completed result, not a progress update.
compress_summary
Not applicableAdvisoryApplies when: Hark provides a summary.
Requirement: Put the summary in one document bubble and keep it materially shorter than the source.
Not applicable. The user requested a researched list rather than a summary of a source.
follow_summary_instructions
Not applicableAdvisoryApplies when: The user requests a summary with a specified length, format, audience, focus, or reading level.
Requirement: Follow the requested summary constraints when the draft carries them and they remain compatible with the required document-bubble delivery.
Not applicable. No summary with specified constraints was requested.
use_default_summary_length
Not applicableAdvisoryApplies when: The user requests a summary without specifying a length or format.
Requirement: Use one document bubble whose content is normally no more than a couple hundred words, extending only when the source's section count requires it.
Not applicable. No unconstrained summary was requested.
preserve_summary_skeleton
Not applicableAdvisoryApplies when: Hark provides a summary.
Requirement: Keep the source's own skeleton while making each section or act a short numbered line.
Not applicable. The response is not a summary of a sectioned or acted source.
preserve_summary_order
Not applicableAdvisoryApplies when: Hark summarizes a source with sections or acts.
Requirement: Preserve the source's section or act order and do not drop one.
Not applicable. The response is not summarizing sections or acts.
keep_summary_qualifications_local
Not applicableAdvisoryApplies when: A summarized statement needs a qualification.
Requirement: Keep the qualification next to the summarized statement it modifies.
Not applicable. No source summary requiring local qualifications is provided.
use_summary_numbered_lines
Not applicableAdvisoryApplies when: Hark formats a structured-source summary.
Requirement: Use short numbered lines inside the document bubble instead of flat prose bubbles.
Not applicable. No structured-source summary is provided.
state_blocker_and_impact
Not applicableAdvisoryApplies when: Hark reports that it cannot complete all or part of the task.
Requirement: State what failed in user terms and which part of the task it affects.
Not applicable. The delivered response reports no blocker or incomplete task.
present_partial_result_before_blocker_detail
Not applicableAdvisoryApplies when: Hark has a useful partial result and also reports a blocker.
Requirement: Present the partial result first and keep any blocker explanation compact.
Not applicable. The response does not combine a partial result with a blocker.
give_one_concrete_next_step
Not applicableAdvisoryApplies when: The user must act before Hark can continue.
Requirement: State one concrete next step only when the draft offers it.
Not applicable. The user does not need to act before Hark can continue.
avoid_internal_error_details
Not applicableAdvisoryApplies when: Hark reports a blocker to a user who is not debugging Hark.
Requirement: Do not expose stack traces, provider payloads, internal tool names, or implementation details.
Not applicable. No blocker or internal error is reported.
avoid_repeated_apology
Not applicableAdvisoryApplies when: Hark reports a blocker or failure.
Requirement: Avoid repeated apologies and generic failure language.
Not applicable. The response contains no apology or failure language.
omit_running_task_updates
Not applicableAdvisoryApplies when: The input says a task is still running.
Requirement: Send no response about the running task. Do not claim a lack of access, suggest the user do it, or announce that work continues.
Not applicable. The input does not indicate that the task remains running when the response is delivered.
preserve_code_exactly
Not applicableAdvisoryApplies when: The draft contains a code block the user needs.
Requirement: Copy the code byte for byte into one code bubble with its language and a short sentence-case title.
Not applicable. No user-needed code block appears in the draft or delivered response.
preserve_document_exactly
Not applicableAdvisoryApplies when: The draft contains an email, message, template, letter, exact quote, or list meant for use elsewhere.
Requirement: Copy the full text byte for byte into one document bubble. A message the user is meant to send, paste, or forward is always a document bubble, never prose. A composed summary card is the only exception.
Not applicable. The draft contains no email, message, template, letter, exact quote, or reusable document requiring byte-exact delivery.
preserve_attachment_names
Not applicableAdvisoryApplies when: The input lists an attachment riding with the reply.
Requirement: Put each attachment in its own matching attachment bubble and use the attachment's exact input name.
Not applicable. No attachments ride with the reply.