Skip to content
Back to skills

Harness Mcp Scan

ASecurity

Static security scan of a harness's declared MCP surface via `harness mcp-scan <path>`. Reads `.mcp/servers.json` + `.harness/claims.json`. Pure-read, no dispatch. Exits 1 on findings at or above `--fail-on` severity.

  • 73,733 stars
  • 0 votes
  • 0 copies
  • 3 views
  • Added September 2, 2026
ai-agentsgobashnodesecurity

Works with

  • mcp

Security analysis

A100/100

Scanned September 27, 2026

npx -y skills add ruvnet/ruflo --skill harness-mcp-scan --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Harness Mcp Scan?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Harness Mcp Scan
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/ruvnet-harness-mcp-scan/badge)](https://www.skillsdirectory.com/skills/ruvnet-harness-mcp-scan)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: harness-mcp-scan
description: Static security scan of a harness's declared MCP surface via `harness mcp-scan <path>`. Reads `.mcp/servers.json` + `.harness/claims.json`. Pure-read, no dispatch. Exits 1 on findings at or above `--fail-on` severity.
argument-hint: "[--path .] [--fail-on low|medium|high] [--format table|json]"
allowed-tools: Bash
---

Calls `harness mcp-scan` to enumerate every declared MCP server + tool
and flag policy / permission / dependency issues. Never executes any
tool; pure static analysis.

## Algorithm

Implementation: [`scripts/mcp-scan.mjs`](../../scripts/mcp-scan.mjs).

1. Invoke the pinned `harness` binary (`metaharness@~0.4.1`, resolved from a
   local install or the one-time `~/.ruflo/metaharness-cache-<pin>` cache —
   never `@latest`): `harness mcp-scan <path> --json`.
2. Parse `findings[]` with `{ severity, id, server, tool, message }`.
3. `--fail-on <severity>`: exit 1 when any finding is at or above that
   level. Default `high`.
4. Output JSON (default) or markdown table.

## Severity rank

| Severity | Rank |
|---|---:|
| low | 1 |
| medium | 2 |
| high | 3 |

`--fail-on high` (default) only fails on HIGH; `--fail-on medium` also
fails on MEDIUM; `--fail-on low` fails on any finding.

## CI integration

```yaml
- name: MCP static scan
  run: node plugins/ruflo-metaharness/scripts/mcp-scan.mjs --fail-on high
```

The exit code is the only thing CI watches; the JSON output goes to
artifacts for human review.

## Graceful degradation

When `harness` binary is unavailable (no network, blocked registry),
emits structured `{ degraded: true, reason: 'metaharness-not-available' }`
and exits 0. Ruflo continues — ADR-150 architectural constraint.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…