Skip to content
Back to skills

Adr

ASecurity

- Status: accepted - Date: 2026-09-29

  • 21 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 4, 2026
ai-agentsgit

Works with

  • claude code
  • mcp

Security analysis

A100/100

Pro scans all 21 files and shows the line behind each finding

Scanned October 4, 2026

npx -y skills add melodic-software/claude-code-plugins --skill adr --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Adr?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Adr
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/melodic-software-adr-claude-code-plugins/badge)](https://www.skillsdirectory.com/skills/melodic-software-adr-claude-code-plugins)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
# Place the machine profile as a harness-ops skill

- Status: accepted
- Date: 2026-09-29

## Context

The [machine profile design](https://github.com/melodic-software/claude-code-plugins/blob/9a0d6f5cf47098fa73bb4b8bb41336be1945c70e/docs/specs/machine-profile-design.md) (issue #4666) describes a
re-runnable profile that discovers host facts once, stores them, and hands each plugin's `setup`
the answers. The design needs one owner. Two placements were on the table: a skill in
`harness-ops`, or a new plugin.

Three existing surfaces sit next to it:

- `harness-ops` owns fleet state and ships `prerequisites` (probes the binaries each enabled plugin
  declares) and `inventory` (lists what this machine can invoke), the two skills the profile reads.
- `machine-health` owns severity, trend, history, and reporting for host findings.
- `harness-config` audits Claude Code configuration files and `harness-memory` audits the
  instruction and memory layer.

## Decision

Place the profile as a skill in `harness-ops`, not as a new plugin.

- **Why not a new plugin.** A new plugin would be a third owner of host facts beside
  `harness-ops` and `machine-health`, and would re-declare tool knowledge the `prerequisites.json`
  manifests already hold.
- **machine-health.** The profile is not a second drift checker. It is the host-fact document
  that machine-health's declared-configuration drift check consumes. The profile records observed
  facts, verdicts, and provenance, and assigns no severity and keeps no history. machine-health
  reads the document and reports findings in its own schema, and does no option discovery. Until
  that check exists, the profile's `diff` is the only consumer.
- **harness-config and harness-memory.** They audit files Claude Code reads (settings, hooks, MCP
  configuration, `CLAUDE.md`, rules, auto-memory) for correctness against upstream docs. The
  profile records what the host contains (binaries, identity domains, tree boundaries, roots),
  not whether a Claude Code file is correct. Where a value belongs to one of those surfaces, the
  profile records the observation and that surface's audit stays the judge of the file.

## Status scope

Accepted. The skill, its scripts, its tests and the `harness-ops` version bump are authorized. The
invocation-mode change (class (ii) and the hidden `setup` skills) and any change to the setup
contract are not part of this decision.

## Consequences

The skill's directory is under `plugins/harness-ops/skills/`. A move to a new plugin would
supersede this record.

Files in this skill

  • 0001-defer-gitbook-as-knowledge-vault-backend.md7 KB
  • 0002-default-on-ai-review-advisory-with-earned-promotion.md29.9 KB
  • 0003-verification-guards-earn-default-on-by-measured-precision.md9.2 KB
  • 0004-rightsize-instruction-surfaces-by-incumbent-first-arbitration.md33 KB
  • 0005-bound-instruction-surface-work-by-question-not-population.md31.7 KB
  • 0006-scope-model-doctrine-per-version-behind-a-promotion-gate.md4.7 KB
  • 0007-host-per-model-doctrine-outside-skill-private-surfaces.md9.5 KB
  • 0008-admit-only-present-text-defects-to-the-instruction-audit-catalog.md6.3 KB
  • 0009-report-the-permission-plane-as-in-effect-and-never-write-to-it.md4.5 KB
  • 0010-merge-findings-across-producers-and-mark-consumption-explicitly.md7 KB
  • 0011-resolve-routine-prerequisites-per-identity-declared-over-detected.md12.7 KB
  • 0012-dispatch-video-sources-through-a-static-adapter-registry.md1.8 KB
  • 0013-keep-storage-format-identifiers-stable-across-renames.md1.7 KB
  • 0014-resolve-seam-engine-plugin-canonical-and-adapters-consumer-first.md2.8 KB
  • 0015-bind-the-tracker-at-repo-root-with-an-allowlisted-personal-overlay.md4.6 KB
  • 0016-source-skill-recommendation-from-the-catalog-not-the-listing.md13.8 KB
  • 0017-ship-the-product-code-lane-as-its-own-skill.md5.1 KB
  • 0018-express-team-shared-conventions-as-consumer-convention-docs.md6.7 KB
  • 0018-treat-the-plugin-as-the-encapsulation-boundary-for-skill-citation.md19.8 KB
  • 0019-share-code-across-plugins-by-vendoring-with-a-sync-gate.md12.3 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…