Deepsec Documentation Guide
vercel-labs/deepsec
Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.
A skill your agent uses when an agent says a test, VM, proof, evaluator, or release gate is overloaded, too strict, blocking staging, or causing false positives; split checks by profile, measure the…
$ npx skills add AnastasiyaW/codex-claude-code-config --skill harness-feedback -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install AnastasiyaW/codex-claude-code-config harness-feedback --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/AnastasiyaW/codex-claude-code-config.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/development/harness-feedback .claude/skills/harness-feedback && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "harness-feedback" agent skill from https://github.com/AnastasiyaW/codex-claude-code-config/tree/main/skills/development/harness-feedback into .claude/skills/harness-feedback/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "harness-feedback", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/AnastasiyaW/codex-claude-code-config/tree/main/skills/development/harness-feedbackType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add AnastasiyaW/codex-claude-code-config --skill harness-feedback -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install AnastasiyaW/codex-claude-code-config harness-feedback --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/AnastasiyaW/codex-claude-code-config.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/development/harness-feedback .agents/skills/harness-feedback && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "harness-feedback" agent skill from https://github.com/AnastasiyaW/codex-claude-code-config/tree/main/skills/development/harness-feedback into .agents/skills/harness-feedback/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "harness-feedback", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add AnastasiyaW/codex-claude-code-config --skill harness-feedback -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install AnastasiyaW/codex-claude-code-config harness-feedback --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/AnastasiyaW/codex-claude-code-config.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/development/harness-feedback .cursor/skills/harness-feedback && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "harness-feedback" agent skill from https://github.com/AnastasiyaW/codex-claude-code-config/tree/main/skills/development/harness-feedback into .cursor/skills/harness-feedback/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "harness-feedback", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/AnastasiyaW/codex-claude-code-config.git --path skills/development/harness-feedback--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add AnastasiyaW/codex-claude-code-config --skill harness-feedback -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install AnastasiyaW/codex-claude-code-config harness-feedback --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/AnastasiyaW/codex-claude-code-config.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/development/harness-feedback .gemini/skills/harness-feedback && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "harness-feedback" agent skill from https://github.com/AnastasiyaW/codex-claude-code-config/tree/main/skills/development/harness-feedback into .gemini/skills/harness-feedback/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "harness-feedback", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install AnastasiyaW/codex-claude-code-config harness-feedbackInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add AnastasiyaW/codex-claude-code-config --skill harness-feedback -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/AnastasiyaW/codex-claude-code-config.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/development/harness-feedback .github/skills/harness-feedback && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "harness-feedback" agent skill from https://github.com/AnastasiyaW/codex-claude-code-config/tree/main/skills/development/harness-feedback into .github/skills/harness-feedback/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "harness-feedback", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add AnastasiyaW/codex-claude-code-config --skill harness-feedback -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install AnastasiyaW/codex-claude-code-config harness-feedback --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/AnastasiyaW/codex-claude-code-config.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/development/harness-feedback .opencode/skills/harness-feedback && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "harness-feedback" agent skill from https://github.com/AnastasiyaW/codex-claude-code-config/tree/main/skills/development/harness-feedback into .opencode/skills/harness-feedback/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "harness-feedback", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
harness-feedbackA skill your agent uses when an agent says a test, VM, proof, evaluator, or release gate is overloaded, too strict, blocking staging, or causing false positives; split checks by profile, measure the…
Harness Feedback is an agent skill from AnastasiyaW/codex-claude-code-config. Use when an agent says a test, VM, proof, evaluator, or release gate is overloaded, too strict, blocking staging, or causing false positives; split checks by profile, measure the burden, preserve high-risk evidence, and verify the smallest corrected workflow. Do not use for ordinary test selection, a single test failure, or a full security audit without a harness-scope question.
Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Failing and flaky tests and Security review. The repository describes itself as: Claude Code, Codex, and multi-agent configuration system: principles, hooks, skills, and workflow patterns for AI-assisted development. The licence is MIT.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 67709af. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Harness Feedback loads about 1k tokens when it runs. Until then it costs about 100 tokens; SKILL.md has 472 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from AnastasiyaW/codex-claude-code-config at commit 67709af, republished under its MIT licence (© AnastasiyaW). 472 words, ~1,041 tokens.
.claude/skills/harness-feedback/SKILL.md (or your agent's skills folder).Treat "the harness is too strict" as an engineering finding, not as permission to disable a safety check. Find the boundary that owns the mismatch and move the check to the narrowest profile that actually needs its evidence.
Use these profiles unless the project has a more specific, documented contract:
| Profile | Purpose | Typical blocking checks |
|---|---|---|
staging-smoke | Fast proof that the changed build starts and the critical path works | build, focused regression, one stable smoke/contract check |
security-proof | Prove an adversarial or trust-boundary claim | hostile tests, source/collector proof, fresh-context evaluator |
release-attestation | Prove the exact releasable artifact and its identity | signing, Authenticode/tool identity, installer/package checks |
nightly-stress | Find intermittent and capacity failures | race, stress, AV/OS matrix, long-running evals |
staging-smoke must not require signing, production credentials, a release
certificate, or a long VM stress run. security-proof may run on an unsigned
staging build when its claim is source or runtime behavior. A release check may
remain blocking for release promotion without becoming a per-edit gate.
For every overload signal, record:
Use the deterministic harness-load-advisor.py signal as an intake event. It
stores metadata outside the repository and forces the final report to name the
mismatch. Durable policy changes belong in Git; raw session traces do not.
Do not write "overkill" and move on. Report:
Harness feedback: OVERLOAD | CLEAR
Requested profile: staging-smoke | security-proof | release-attestation | nightly-stress
Mis-scoped gate: <name>
Evidence: <command, result, elapsed time, or explicit missing proof>
Correction: <profile split or rule change>
Verification: <before/after commands and result>
Residual risk: <what remains intentionally gated and where>| Symptom | Likely cause | Action |
|---|---|---|
| Staging smoke asks for signing | Release gate leaked into staging profile | split release-attestation and run the smoke on the unsigned staging artifact |
| Security proof blocks on a production VM | Runtime environment and release identity are coupled | keep the VM, remove release-only assertions from the security profile |
| Same gate fails repeatedly | Wrong scope, flaky boundary, or missing fixture | classify the failure and add a focused reproducer; never silently retry |
| Agent says "tests passed" with no profile | Evidence contract is incomplete | require the report fields above and the exact command/result |
| Fix removes a safety check | Causal ownership was not traced | restore the check, document the narrower boundary, and re-verify it there |
© AnastasiyaW, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/development/harness-feedback of AnastasiyaW/codex-claude-code-config.
Open the folder on GitHubat commit 67709af
Harness Feedback next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Harness Feedback this skillAnastasiyaW/codex-claude-code-config | 154 | — | ~1k | Automated safety check: Pass | MIT | |
| Deepsec Documentation Guidevercel-labs/deepsec | 8.1k | — | ~956 | Automated safety check: Pass | Apache-2.0 | |
| Kubernetes Network Security Auditkubeshark/kubeshark | 12k | — | ~7.3k | Automated safety check: Notes | Apache-2.0 | |
| Native Dependency Updatemono/SkiaSharp | 5.6k | — | ~4.1k | Automated safety check: Pass | MIT | |
| Semgrep Security Scantrailofbits/skills | 7.5k | — | ~3.7k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Skillward AuditFangcun-AI/SkillWard | 143 | — | ~2.9k | Automated safety check: Pass | Custom licence |
vercel-labs/deepsec
Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.
kubeshark/kubeshark
Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.
mono/SkiaSharp
Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.
trailofbits/skills
Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.
Fangcun-AI/SkillWard
Security-audit a third-party skill bundle (folder with SKILL.md, or .zip / .tar.gz archive) before installing it, using the SkillWard cloud scanner.
TheDecipherist/claude-code-mastery
Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.
AnastasiyaW/codex-claude-code-config
Find likely software bugs in a codebase, rank concrete bug candidates, and prove or reject them with focused regression tests before proposing a fix.
AnastasiyaW/codex-claude-code-config
A skill your agent uses when implementing Motion or Framer Motion in React/JavaScript: interactive UI components, micro-interactions, gestures, layout or page transitions, and scroll-based animation.
AnastasiyaW/codex-claude-code-config
Plan-based verification - freeze acceptance criteria before building, then verify after with an independent fresh-context agent (the builder must not verify their own work).
AnastasiyaW/codex-claude-code-config
Написание и запуск Claude Code dynamic workflows (JS-оркестратор субагентов).
AnastasiyaW/codex-claude-code-config
A skill your agent uses when: NotebookLM, notebooklm MCP, large documentation sets, courses, books, papers, or citation-backed research are mentioned.
AnastasiyaW/codex-claude-code-config
Validate a proposed DeepSeek API integration before any key or project context is sent: check thinking-mode tool-call history, strict-schema assumptions, bounded output, and provider data boundaries.
Categories
A skill your agent uses when an agent says a test, VM, proof, evaluator, or release gate is overloaded, too strict, blocking staging, or causing false positives; split checks by profile, measure the…. Harness Feedback is an agent skill from AnastasiyaW/codex-claude-code-config. Use when an agent says a test, VM, proof, evaluator, or release gate is overloaded, too strict, blocking staging, or causing false positives; split checks by profile, measure the burden, preserve high-risk evidence, and verify the smallest corrected workflow.
Harness Feedback fits situations like: an agent says a test; release gate is overloaded; blocking staging; causing false positives.
Run `npx skills add AnastasiyaW/codex-claude-code-config --skill harness-feedback -a claude-code`. Or copy the skill folder (skills/development/harness-feedback in AnastasiyaW/codex-claude-code-config) into .claude/skills/harness-feedback in your project. Claude Code loads it when a task matches its description.
Run `npx skills add AnastasiyaW/codex-claude-code-config --skill harness-feedback -a codex`. Or copy the skill folder (skills/development/harness-feedback in AnastasiyaW/codex-claude-code-config) into .agents/skills/harness-feedback in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add AnastasiyaW/codex-claude-code-config --skill harness-feedback -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/harness-feedback, .gemini/skills/harness-feedback, .github/skills/harness-feedback and .opencode/skills/harness-feedback in your project.
SKILL.md names no scripts, command-line tools or credentials: Harness Feedback is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Harness Feedback is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1k tokens (SKILL.md is roughly 4.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Harness Feedback: Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Kubernetes Network Security Audit (kubeshark/kubeshark, 12k stars), Native Dependency Update (mono/SkiaSharp, 5.6k stars) and Semgrep Security Scan (trailofbits/skills, 7.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
AnastasiyaW (a GitHub user) maintains it in AnastasiyaW/codex-claude-code-config, which has 154 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on October 9, 2026.
Source: AnastasiyaW/codex-claude-code-config on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.