Skip to content
Back to skills

Harness Threat Model

ASecurity

Enterprise-review-grade threat model from `harness threat-model <path>`. Categorizes MCP-surface threats; emits `worst: 'clean'|'low'|'medium'|'high'` + per-threat findings. Pure-read.

  • 73,733 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 2, 2026
ai-agentsgobashsecurity

Works with

  • mcp

Security analysis

A100/100

Scanned September 27, 2026

npx -y skills add ruvnet/ruflo --skill harness-threat-model --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Harness Threat Model?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Harness Threat Model
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/ruvnet-harness-threat-model/badge)](https://www.skillsdirectory.com/skills/ruvnet-harness-threat-model)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: harness-threat-model
description: Enterprise-review-grade threat model from `harness threat-model <path>`. Categorizes MCP-surface threats; emits `worst: 'clean'|'low'|'medium'|'high'` + per-threat findings. Pure-read.
argument-hint: "[--path .] [--fail-on clean|low|medium|high] [--format table|json]"
allowed-tools: Bash
---

The companion to `harness-mcp-scan` for enterprise security reviews.
Where mcp-scan is a per-server static lint, threat-model produces a
categorized report suitable for sharing with an InfoSec team.

## Algorithm

Implementation: [`scripts/threat-model.mjs`](../../scripts/threat-model.mjs).

1. Invoke the pinned `harness` binary (`metaharness@~0.4.1`, resolved from a
   local install or the one-time `~/.ruflo/metaharness-cache-<pin>` cache —
   never `@latest`): `harness threat-model <path> --json`.
2. Parse `{ worst, findings[] }`.
3. `--fail-on <severity>`: exit 1 when `worst >= fail-on`. Default `high`.

## Severity rank

| Severity | Rank |
|---|---:|
| clean | 0 |
| low | 1 |
| medium | 2 |
| high | 3 |

## When to use

- Pre-launch review: include the JSON output in the release-readiness
  packet sent to security.
- Periodic audit: schedule via the planned `oia-audit` background
  worker (ADR-150 Phase 2) to detect MCP-surface drift.

## Graceful degradation

Same pattern as the other skills: when `harness` is absent, emit
`{ degraded: true }` and exit 0. ADR-150 architectural constraint.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…