A skill your agent uses when auditing HARNESS.md, pre-commit hooks, pre-push hooks, architecture gates, or CI workflows for tunacode-cli.

MITAuto-check passed

Install Audit Harness

skills CLI
$ npx skills add alchemiststudiosDOTai/tunacode --skill audit-harness -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install alchemiststudiosDOTai/tunacode audit-harness --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/alchemiststudiosDOTai/tunacode.git skills-src && mkdir -p .claude/skills && cp -r skills-src/docs/skills/audit-harness .claude/skills/audit-harness && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit-harness
GitHub stars
125
Token cost
~769 tokens
SKILL.md length
318 words
Files
1
Skills in repo
2
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when auditing HARNESS.md, pre-commit hooks, pre-push hooks, architecture gates, or CI workflows for tunacode-cli.

  • Works in 8 steps: HARNESS.md → .pre-commit-config.yaml → Makefile → …
  • Auditing HARNESS.md
  • SKILL.md covers Trigger, Hard Rules, Source Of Truth Order and Manual Audit Procedure, plus 1 more section
  • Calls uv and make

What it does

Audit Harness is an agent skill from alchemiststudiosDOTai/tunacode. Use when auditing HARNESS.md, pre-commit hooks, pre-push hooks, architecture gates, or CI workflows for tunacode-cli. This skill treats any mismatch, skipped gate, or failing check as a critical failure and requires manual one-by-one execution rather than make targets, batch wrappers, or summary-only audits.

Its SKILL.md is about 770 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with OpenAI. The repository describes itself as: 🍣 TunaCode AI CLI coding agent with safe git branches, rich tools & multi-LLM support. The licence is MIT.

When your agent uses it

  • Auditing HARNESS.md
  • Pre-commit hooks
  • Architecture gates
  • CI workflows for tunacode-cli

Example prompts

  • “/audit-harness”

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. HARNESS.md
  2. .pre-commit-config.yaml
  3. Makefile
  4. tests/test_dependency_layers.py
  5. scripts/grimp_layers_report.py
  6. .github/workflows/*.yml
  7. docs/git/practices.md
  8. AGENTS.md

What it can do on your machine

Read from SKILL.md and the folder at commit 1b39d1f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • uv
    • make

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use uv, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Audit Harness loads about 769 tokens when it runs. Until then it costs about 81 tokens; SKILL.md has 318 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~81
When it runs · the whole SKILL.md, loaded when a task matches
~769

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from alchemiststudiosDOTai/tunacode at commit 1b39d1f, republished under its MIT licence (© alchemiststudiosDOTai). 318 words, ~769 tokens.

Download SKILL.mdSave it as .claude/skills/audit-harness/SKILL.md (or your agent's skills folder).
name
audit-harness
description
Use when auditing HARNESS.md, pre-commit hooks, pre-push hooks, architecture gates, or CI workflows for tunacode-cli. This skill treats any mismatch, skipped gate, or failing check as a critical failure and requires manual one-by-one execution rather than make targets, batch wrappers, or summary-only audits.
when_to_read
Auditing HARNESS.md, Verifying harness accuracy, Running pre-commit or pre-push hooks manually
summary
Strict procedure for auditing harness, hook, and CI enforcement in tunacode-cli.
last_updated
2026-04-04

Audit Harness

HARNESS.md is mission-critical. Audit it with zero tolerance.

Trigger

Use this skill when the user asks to:

  • audit HARNESS.md
  • verify harness accuracy
  • run pre-commit or pre-push hooks manually
  • confirm architecture or CI gates
  • explain what actually enforces the harness

Hard Rules

  • Treat any mismatch, omission, skipped gate, auto-fix, or failing check as a critical failure.
  • Never describe results as "mostly passing", "just one failure", or equivalent minimization.
  • State the exact failure first.
  • Explain the finding before changing code or docs.
  • Do not proceed with a fix until the user tells you to proceed.
  • During harness audits, never use make check, scripts/run_gates.py, or any loop/script wrapper as the primary audit path.
  • Run checks manually, one by one, in the same order they appear in the source-of-truth config.
  • If a hook modifies files, report the exact files immediately.
  • Do not revert hook changes unless the user explicitly asks.

Source Of Truth Order

Read these first:

  1. HARNESS.md
  2. .pre-commit-config.yaml
  3. Makefile
  4. tests/test_dependency_layers.py
  5. scripts/grimp_layers_report.py
  6. .github/workflows/*.yml
  7. docs/git/practices.md
  8. AGENTS.md

Manual Audit Procedure

Pre-commit
  1. Enumerate the active pre-commit hooks from .pre-commit-config.yaml.
  2. Start at the top.
  3. Run each hook manually:
bash
uv run pre-commit run <hook-id> --all-files
  1. After each hook: state Passed, Failed, Skipped, or Modified files.
  2. If a hook fails, stop and explain why before proposing a fix.
Pre-push
  1. Enumerate the active pre-push hooks from .pre-commit-config.yaml.
  2. Run each one manually, one by one:
bash
uv run pre-commit run <hook-id> --hook-stage pre-push --all-files
  1. Treat any failure as critical.
Architecture
  • tests/test_dependency_layers.py is the source of truth for grimp enforcement.
  • scripts/grimp_layers_report.py is report generation only.
  • scripts/run_gates.py is supplemental only and not canonical.
CI/CD

For each workflow, label it clearly as one of:

  • local source of truth
  • local supplemental check
  • CI enforcement
  • CI artifact generation
  • CI report / issue automation

If wording in HARNESS.md hides an important behavior, call that a critical documentation failure.

Response Style

  • Be short.
  • Be exact.
  • One failure is a critical failure.
  • Do not soften language.

© alchemiststudiosDOTai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in docs/skills/audit-harness of alchemiststudiosDOTai/tunacode.

Open the folder on GitHubat commit 1b39d1f

Compare with similar skills

Audit Harness next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Audit Harness compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Audit Harness this skillalchemiststudiosDOTai/tunacode125—~769Automated safety check: PassMIT
Geo Fundamentalswasp-lang/wasp19k9 repos~861Automated safety check: PassMIT
AI SDKvercel-labs/ai-facts16821 repos~1.2kAutomated safety check: PassNone
AI Image Generation and Editingzhayujie/CowAgent47k—~1.3kAutomated safety check: PassMIT
ModLens Image Vision Bridgeliustack/modlens4.2k1 repos~1.3kAutomated safety check: NotesMIT
PR Design DocOpenHands/OpenHands90k—~2.4kAutomated safety check: PassMIT

Similar skills

  • Geo Fundamentals

    wasp-lang/wasp

    Generative Engine Optimization for AI search engines (ChatGPT, Claude, Perplexity).

    19k GitHub starsUsed in 9 repos~861 tokens
    Marketing & SEOAuto-check passed
  • AI SDK

    vercel-labs/ai-facts

    Official

    Answer questions about the AI SDK and help build AI-powered features.

    168 GitHub starsUsed in 21 repos~1.2k tokens
    AI & LLM EngineeringAuto-check passed
  • Generates or edits images from text prompts through a Python script that picks an image backend based on which API keys are configured.

    47k GitHub stars~1.3k tokensUpdated today
    Media & CreativeAuto-check passed
  • Gives text-only models sight by running the modlens CLI on an image path or URL and returning structured JSON evidence with transcribed text, layout and semantics.

    4.2k GitHub starsUsed in 1 repo~1.3k tokens
    AI & LLM EngineeringAuto-check: notes
  • PR Design Doc

    OpenHands/OpenHands

    For a non-trivial pull request, write a self-contained HTML design doc under the temporary .pr/ directory and link a visibility-appropriate preview in the PR description, so maintainers grasp the…

    90k GitHub stars~2.4k tokensUpdated today
    DevelopmentAuto-check passed
  • Bibi

    JimmyLv/BibiGPT-v1

    BibiGPT CLI for summarizing videos, audio, and podcasts directly in the terminal.

    6.2k GitHub starsUsed in 1 repo~885 tokens
    Media & CreativeAuto-check passed

More from alchemiststudiosDOTai/tunacode

  • Pypi Release

    alchemiststudiosDOTai/tunacode

    This skill should be used when releasing tunacode-cli to PyPI.

    125 GitHub stars~2.2k tokensUpdated 3 days ago
    Auto-check passed

Works with

Questions about Audit Harness

What does Audit Harness do?

A skill your agent uses when auditing HARNESS.md, pre-commit hooks, pre-push hooks, architecture gates, or CI workflows for tunacode-cli. Audit Harness is an agent skill from alchemiststudiosDOTai/tunacode.md, pre-commit hooks, pre-push hooks, architecture gates, or CI workflows for tunacode-cli.

When should I use Audit Harness?

Audit Harness fits situations like: auditing HARNESS.md; pre-commit hooks; architecture gates; CI workflows for tunacode-cli.

How do I install Audit Harness in Claude Code?

Run `npx skills add alchemiststudiosDOTai/tunacode --skill audit-harness -a claude-code`. Or copy the skill folder (docs/skills/audit-harness in alchemiststudiosDOTai/tunacode) into .claude/skills/audit-harness in your project. Claude Code loads it when a task matches its description.

How do I install Audit Harness in Codex?

Run `npx skills add alchemiststudiosDOTai/tunacode --skill audit-harness -a codex`. Or copy the skill folder (docs/skills/audit-harness in alchemiststudiosDOTai/tunacode) into .agents/skills/audit-harness in your project. Codex loads it when a task matches its description.

Can I use Audit Harness in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add alchemiststudiosDOTai/tunacode --skill audit-harness -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-harness, .gemini/skills/audit-harness, .github/skills/audit-harness and .opencode/skills/audit-harness in your project.

What does Audit Harness need to run?

Going by SKILL.md and its folder, Audit Harness needs the command-line tools its instructions call (uv and make).

Does Audit Harness access the network?

SKILL.md contains no URLs. Its commands use uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Audit Harness safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Audit Harness use?

Audit Harness is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Audit Harness use?

About 769 tokens (SKILL.md is roughly 3.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Audit Harness?

Skills that share tags, products or a category with Audit Harness: Geo Fundamentals (wasp-lang/wasp, 19k stars), AI SDK (vercel-labs/ai-facts, 168 stars), AI Image Generation and Editing (zhayujie/CowAgent, 47k stars) and ModLens Image Vision Bridge (liustack/modlens, 4.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Audit Harness?

alchemiststudiosDOTai (a GitHub organization) maintains it in alchemiststudiosDOTai/tunacode, which has 125 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on October 5, 2026.

Source: alchemiststudiosDOTai/tunacode on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.