Agent skill

Trailofbits Harness

by autonomous-ai in autonomous-ai/openharness

Use in every Trail of Bits Skills workspace inside Harness, before any audit skill — the findings.json format the report pane is built from, which Trail of Bits skill serves which audit phase, and…

MITAuto-check passedSecurity

Install Trailofbits Harness

skills CLI
$ npx skills add autonomous-ai/openharness --skill trailofbits-harness -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install autonomous-ai/openharness trailofbits-harness --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/autonomous-ai/openharness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/store/agents/trailofbits-skills/skills/trailofbits-harness .claude/skills/trailofbits-harness && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
trailofbits-harness
GitHub stars
1.1k
Token cost
~1.5k tokens
SKILL.md length
600 words
Files
1
Skills in repo
100
Repo updated
First seen
Licence
MIT

At a glance

Use in every Trail of Bits Skills workspace inside Harness, before any audit skill — the findings.json format the report pane is built from, which Trail of Bits skill serves which audit phase, and…

  • Tasks that involve Subagents
  • SKILL.md covers findings.json, Which skill serves which phase, Plugin features, provided here and Tools
  • Calls semgrep

What it does

Trailofbits Harness is an agent skill from autonomous-ai/openharness. Use in every Trail of Bits Skills workspace inside Harness, before any audit skill — the findings.json format the report pane is built from, which Trail of Bits skill serves which audit phase, and how their plugin features (plugin root, named sub-agents, Workflow scripts, fp-check's gates) work when their skills are linked rather than installed as plugins.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Subagents. The repository describes itself as: The ultimate harness for coding agents and beyond. All your agents. All your machines. One command center. Start with code, then follow your curiosity and build across… The licence is MIT.

When your agent uses it

  • Tasks that involve Subagents

Example prompts

  • “/trailofbits-harness”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 50da5db. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • semgrep

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Trailofbits Harness loads about 1.5k tokens when it runs. Until then it costs about 95 tokens; SKILL.md has 600 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~95
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from autonomous-ai/openharness at commit 50da5db, republished under its MIT licence (© autonomous-ai). 600 words, ~1,451 tokens.

Download SKILL.mdSave it as .claude/skills/trailofbits-harness/SKILL.md (or your agent's skills folder).
name
trailofbits-harness
description
Use in every Trail of Bits Skills workspace inside Harness, before any audit skill — the findings.json format the report pane is built from, which Trail of Bits skill serves which audit phase, and how their plugin features (plugin root, named sub-agents, Workflow scripts, fp-check's gates) work when their skills are linked rather than installed as plugins.

A Trail of Bits audit in Harness

Trail of Bits' skills are the method; this skill only says how their work lands in the report pane and how the plugin features they assume are provided here. It changes none of their instructions.

findings.json

security-audit/findings.json is the one file you edit. "$TOB_REPORT" checks it, rebuilds the pane and the Markdown report from it, and prints every entry it had to leave out and why — fix those before moving on.

json
{
  "spec": 1,
  "target": { "name": "shop-api", "path": ".", "commit": "3f2c9a1…", "scope": ["src/", "api/"] },
  "phase": "review",
  "final": false,
  "summary": "Markdown: what was audited, how, and the headline risks.",
  "findings": [
    {
      "id": "F-1",
      "title": "SQL query built from request input",
      "severity": "high",
      "status": "unverified",
      "category": "injection",
      "source": "static-analysis/semgrep",
      "location": [{ "file": "src/db.py", "line": 42 }],
      "description": "Markdown: what is wrong.",
      "evidence": "Markdown: the data flow, the rule that fired, the fp-check verdict and its reasons.",
      "recommendation": "Markdown: how to fix it."
    }
  ]
}
  • phase: scope → context → scan → review → verify → report. The header's strip is this.
  • severity: high, medium, low, informational, undetermined — Trail of Bits' own scale.
  • status: unverified when found, then confirmed or false-positive after fp-check. False positives stay in the file (the report lists them as dismissed, with their evidence).
  • id: F-1, F-2, … in the order found; never reuse one. Paths are relative to the target.
  • The Markdown fields render paragraphs, - lists, code, fenced code, bold and italics — nothing else. Everything is escaped, so quoting hostile strings from the code is safe.
  • The report is ready (ready in the header) only when final is true and nothing is unverified.

Which skill serves which phase

PhaseTrail of Bits skill (plugin)When
contextaudit-context-buildingalways first: understand before hunting
scansemgrep, codeql when installed, sarif-parsing (static-analysis)always
scansupply-chain-risk-auditora lockfile or manifest is present
scansharp-edgesAPIs, configuration and defaults that invite misuse
scanagentic-actions-auditor.github/workflows/ exists
scanc-review / rust-reviewC/C++ / Rust code in scope
reviewvulnerability-triage-brocardstriage each candidate before deep work
reviewvariant-analysisa confirmed bug suggests siblings elsewhere
reviewdifferential-reviewthe person asks about a change, branch or PR
verifyfp-checkevery finding, before it is confirmed

Turn each skill's output — SARIF, ledgers, reports — into findings.json entries, citing it in source.

Show full SKILL.md (310 more words)Show less

Plugin features, provided here

These skills were written as Claude Code plugins. Harness links their skills into every agent, so the plugin machinery they mention is provided like this:

  • Plugin root. Where a skill uses ${CLAUDE_PLUGIN_ROOT}, ${CODEX_PLUGIN_ROOT} or <plugin_root>, it is $TOB_SKILLS/plugins/<plugin> for the plugin the skill belongs to. Set it on the command that needs it — CLAUDE_PLUGIN_ROOT="$TOB_SKILLS/plugins/c-review" … — and use that path, not a search: a search of . would find copies inside the audited repository.
  • Named sub-agents. When a skill dispatches <plugin>:<agent> (fp-check:poc-builder, rust-review:rust-review-worker, audit-context-building:function-analyzer), start a sub-agent with your own sub-agent tool and give it $TOB_SKILLS/plugins/<plugin>/agents/<agent>.md as its instructions, plus the task the skill describes. Hold it to the tools that file's front matter lists. Where the skill runs several in parallel, run them in parallel.
  • Plugin commands. A /<plugin>:<command> that a skill mentions is a Markdown file, $TOB_SKILLS/plugins/<plugin>/commands/<command>.md (/differential-review:diff-review): read it and follow it, with the arguments the person gave.
  • Workflow scripts. Where a skill calls Claude Code's Workflow tool with a script under <plugin_root>/workflows/, or a command such as /audit-context-building:audit-context that is backed by one, call Workflow with the absolute scriptPath ($TOB_SKILLS/plugins/<plugin>/workflows/<name>.js) and the arguments the skill documents. An agent without a Workflow tool follows the skill's single-unit mode over each unit in scope and says so in the report's summary.
  • fp-check's gates. Its plugin hooks check, before a verification ends, that every phase and gate was done. Here nothing runs them for you: before you set a finding confirmed or false-positive, read the two prompts in $TOB_SKILLS/plugins/fp-check/hooks/hooks.json and check your own work against them; a gap keeps the finding unverified.

Tools

The Semgrep, pip-audit, uv and Python the skills expect are in $TOB_BIN; put it first on each command's PATH: PATH="$TOB_BIN:$PATH" semgrep --metrics=off …. CodeQL and ripgrep are optional here; when they are missing, the skills' own fallbacks apply (toolchain/doctor.sh in the package says which are present).

© autonomous-ai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in store/agents/trailofbits-skills/skills/trailofbits-harness of autonomous-ai/openharness.

Open the folder on GitHubat commit 50da5db

Compare with similar skills

Trailofbits Harness next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Trailofbits Harness compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Trailofbits Harness this skillautonomous-ai/openharness1.1k—~1.5kAutomated safety check: PassMIT
Orchestrate Stageseqra/opentaint162—~806Automated safety check: PassApache-2.0
Figma From Code Discovery Assetsbitovi/ai-enablement-prompts121—~1.4kAutomated safety check: PassMIT
Vulnhunter Runnealbridges/VulnHunter646—~711Automated safety check: PassApache-2.0
Vbs Scan Securitytanviet12/vbsec287—~6.8kAutomated safety check: NotesMIT
Security AuditorArchethect/sc-auditor127—~5.9kAutomated safety check: NotesNone

Similar skills

  • Orchestrate Stage

    seqra/opentaint

    Run one stage of the OpenTaint pipeline by coordinating leaf subagents and deterministic joins.

    162 GitHub stars~806 tokensUpdated yesterday
    SecurityAuto-check passed
  • Figma From Code Discovery Assets

    bitovi/ai-enablement-prompts

    Subagent for figma-from-code Phase 0b. An agent skill from bitovi/ai-enablement-prompts.

    121 GitHub stars~1.4k tokensUpdated 27 days ago
    SecurityAuto-check passed
  • Vulnhunter Run

    nealbridges/VulnHunter

    Unattended VulnHunter operator. An agent skill from nealbridges/VulnHunter.

    646 GitHub stars~711 tokensUpdated yesterday
    SecurityAuto-check passed
  • Vbs Scan Security

    tanviet12/vbsec

    A skill your agent uses when scanning code for security vulnerabilities.

    287 GitHub stars~6.8k tokensUpdated 10 days ago
    SecurityAuto-check: notes
  • Security Auditor

    Archethect/sc-auditor

    Interactive smart contract security audit using Map-Hunt-Attack methodology with static analysis, parallel hunt lanes, skeptic-judge verification, and structured reporting.

    127 GitHub stars~5.9k tokensUpdated 6 mo ago
    SecurityAuto-check: notes
  • Dependency Update Audit

    backnotprop/plannotator

    Audits outdated npm and Bun packages for supply chain integrity before bumping them, deferring risky ones and logging every decision.

    9.2k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check passed

More from autonomous-ai/openharness

All 100 skills in this repo
  • G-code Slicer Tool

    autonomous-ai/openharness

    Slices 3D mesh files into printer-profiled plain G-code through real slicer CLIs, with backend discovery, input inspection, dry runs and static validation.

    1.1k GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • Home Assistant Automation Builder

    autonomous-ai/openharness

    Turns a home-automation request into standard, testable automations.yaml, run against Home Assistant Core's real triggers and verified with its own trace tool.

    1.1k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Score Music Composer

    autonomous-ai/openharness

    Turns a musical brief into LilyPond concert-pitch music, checked parts for each instrument and a playable practice pack.

    1.1k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • OrcaSlicer 3MF and G-code Workflow

    autonomous-ai/openharness

    Turns an STL and explicit printer and material requirements into compared OrcaSlicer plans, an editable 3MF project, checked G-code and a portable handoff.

    1.1k GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • Sheets and Docs Report Builder

    autonomous-ai/openharness

    Builds an editable DOCX report, a formula-driven XLSX workbook and a fresh LibreOffice PDF preview from one structured source file, then checks them together.

    1.1k GitHub stars~708 tokensUpdated today
    Auto-check passed
  • Bambu Labs

    autonomous-ai/openharness

    Dry-run, upload, and cautiously initiate local Bambu Lab print jobs from validated plain .gcode, using Bambu LAN FTPS/MQTT handoffs.

    1.1k GitHub starsUsed in 1 repo~2.1k tokens
    Auto-check: warnings

Questions about Trailofbits Harness

What does Trailofbits Harness do?

Use in every Trail of Bits Skills workspace inside Harness, before any audit skill — the findings.json format the report pane is built from, which Trail of Bits skill serves which audit phase, and…. Trailofbits Harness is an agent skill from autonomous-ai/openharness.json format the report pane is built from, which Trail of Bits skill serves which audit phase, and how their plugin features (plugin root, named sub-agents, Workflow scripts, fp-check's gates) work when their skills are linked rather than installed as plugins.

When should I use Trailofbits Harness?

Trailofbits Harness fits situations like: tasks that involve Subagents.

How do I install Trailofbits Harness in Claude Code?

Run `npx skills add autonomous-ai/openharness --skill trailofbits-harness -a claude-code`. Or copy the skill folder (store/agents/trailofbits-skills/skills/trailofbits-harness in autonomous-ai/openharness) into .claude/skills/trailofbits-harness in your project. Claude Code loads it when a task matches its description.

How do I install Trailofbits Harness in Codex?

Run `npx skills add autonomous-ai/openharness --skill trailofbits-harness -a codex`. Or copy the skill folder (store/agents/trailofbits-skills/skills/trailofbits-harness in autonomous-ai/openharness) into .agents/skills/trailofbits-harness in your project. Codex loads it when a task matches its description.

Can I use Trailofbits Harness in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add autonomous-ai/openharness --skill trailofbits-harness -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/trailofbits-harness, .gemini/skills/trailofbits-harness, .github/skills/trailofbits-harness and .opencode/skills/trailofbits-harness in your project.

What does Trailofbits Harness need to run?

Going by SKILL.md and its folder, Trailofbits Harness needs the command-line tools its instructions call (semgrep). Our summary lists: Python 3.

Does Trailofbits Harness access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Trailofbits Harness safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Trailofbits Harness use?

Trailofbits Harness is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Trailofbits Harness use?

About 1.5k tokens (SKILL.md is roughly 5.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Trailofbits Harness?

Skills that share tags, products or a category with Trailofbits Harness: Orchestrate Stage (seqra/opentaint, 162 stars), Figma From Code Discovery Assets (bitovi/ai-enablement-prompts, 121 stars), Vulnhunter Run (nealbridges/VulnHunter, 646 stars) and Vbs Scan Security (tanviet12/vbsec, 287 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Trailofbits Harness?

autonomous-ai (a GitHub organization) maintains it in autonomous-ai/openharness, which has 1,149 GitHub stars. The repository holds 100 skills in this directory. The repository was last updated on October 8, 2026.

Source: autonomous-ai/openharness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.