Agent skill

Audit Report

by harness in harness/harness-skills

Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.

Apache-2.0Auto-check passedLegal & Compliance

Install Audit Report

skills CLI
$ npx skills add harness/harness-skills --skill audit-report -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install harness/harness-skills audit-report --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/harness/harness-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/audit-report .claude/skills/audit-report && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit-report
GitHub stars
115
Token cost
~1.3k tokens
SKILL.md length
465 words
Files
2 (incl. references)
Skills in repo
24
Repo updated
First seen
Licence
Apache-2.0

At a glance

Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.

  • Works in 6 steps: Discover Available Filters → List Audit Events → Filter by Action Type → …
  • Asked to audit activity
  • SKILL.md covers MCP v2 Tools Used, Instructions, Examples and Error Handling, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Audit Report is an agent skill from harness/harness-skills. Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools. Track user actions, resource changes, authentication events, and access patterns across accounts, organizations, and projects. Use when asked to audit activity, generate compliance reports, investigate security incidents, review user actions, check change logs, or produce SOC2/GDPR/HIPAA audit evidence. Trigger phrases: audit report, audit trail, compliance audit, user activity log, change log, access audit, security…

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/report-templates.md`). Compatibility notes: Requires Harness MCP v2 server (harness-mcp-v2)

It sits in Legal & Compliance, covering SOC 2 and security compliance, Access reviews and audit trails and Privacy and GDPR. It works with Model Context Protocol. The repository describes itself as: A collection of structured AI agent skills that enable Claude Code, Cursor, GitHub Copilot, and other AI coding assistants to create, operate, debug, and govern Harness CI/CD… The licence is Apache-2.0.

When your agent uses it

  • Asked to audit activity
  • Generate compliance reports
  • Investigate security incidents
  • Review user actions

Example prompts

  • “/audit-report”

Requirements

  • Compatibility (from SKILL.md): Requires Harness MCP v2 server (harness-mcp-v2)

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Discover Available Filters
  2. List Audit Events
  3. Filter by Action Type
  4. Filter by Resource Type
  5. Analyze and Correlate
  6. Generate Report

What it can do on your machine

Read from SKILL.md and the folder at commit c25faee. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires Harness MCP v2 server (harness-mcp-v2)

    From compatibility in the SKILL.md frontmatter.

Context cost

Audit Report loads about 1.3k tokens when it runs, and up to ~2.1k if it reads all its reference files. Until then it costs about 144 tokens; SKILL.md has 465 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~144
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from harness/harness-skills at commit c25faee, republished under its Apache-2.0 licence (© harness). 465 words, ~1,317 tokens.

Download SKILL.mdSave it as .claude/skills/audit-report/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
audit-report
description
Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools. Track user actions, resource changes, authentication events, and access patterns across accounts, organizations, and projects. Use when asked to audit activity, generate compliance reports, investigate security incidents, review user actions, check change logs, or produce SOC2/GDPR/HIPAA audit evidence. Trigger phrases: audit report, audit trail, compliance audit, user activity log, change log, access audit, security investigation, who changed what, audit events.
compatibility
Requires Harness MCP v2 server (harness-mcp-v2)
metadata.author
Harness
metadata.version
1.0.0
metadata.mcp-server
harness-mcp-v2
license
Apache-2.0

Audit Report Skill

Generate audit reports and compliance trails using Harness MCP v2 tools.

MCP v2 Tools Used

  • harness_list with resource_type: "audit_event" -- list audit events with filters
  • harness_describe with resource_type: "audit_event" -- discover available filters and fields

Audit events are read-only. You can list and filter them but cannot create, update, or delete them.

Instructions

Step 1: Discover Available Filters
harness_describe(resource_type="audit_event")

Understand the available filter parameters before querying.

Step 2: List Audit Events
harness_list(
  resource_type="audit_event",
  org_id="<org>",           # optional - scope to organization
  project_id="<project>",   # optional - scope to project
  search_term="<user or resource>",  # optional
  page=0,
  size=100
)
Step 3: Filter by Action Type

Filter results by these standard action types:

ActionDescription
CREATEResource creation
UPDATEResource modification
DELETEResource deletion
LOGINUser authentication
LOGOUTSession termination
ACCESSResource access
EXECUTEPipeline execution
Step 4: Filter by Resource Type

Common resource types in audit events:

Resource TypeExamples
PIPELINEPipeline create, update, delete
SECRETSecret access, rotation, deletion
CONNECTORConnector modifications
SERVICEService definition changes
ENVIRONMENTEnvironment configuration changes
USERUser management actions
ROLERole assignment changes
USER_GROUPGroup membership changes
Step 5: Analyze and Correlate
  • Group events by user to identify activity patterns
  • Group events by resource to track change history
  • Correlate timestamps to reconstruct incident timelines
  • Flag anomalies (off-hours activity, unusual access patterns, privilege escalation)
Step 6: Generate Report

Format findings using the templates in references/report-templates.md.

For report templates (General, User Activity, Security) and compliance framework mappings (SOC 2, GDPR, HIPAA), consult references/report-templates.md.

Examples

Generate a 30-day audit report
/audit-report
Generate an audit report for the last 30 days
Investigate a specific user
/audit-report
What has john.doe@company.com been doing in the last 7 days?
Track production changes
/audit-report
Show all pipeline and environment changes in the production project this month
Security investigation
/audit-report
Show all secret access events and privilege changes from last week
Compliance evidence
/audit-report
Generate SOC2 audit evidence for Q4 covering access control and change management

Error Handling

ErrorCauseSolution
No audit events returnedTime range too narrow or wrong scopeBroaden time range; verify org_id/project_id
Access deniedUser lacks audit view permissionsRequest core_audit_view permission
Pagination incompleteMore events than page sizeIncrement page parameter until all pages fetched
Search term returns nothingUser ID format mismatchTry email, username, and display name variants
Show full SKILL.md (169 more words)Show less

Performance Notes

  • Paginate through all results before generating the report. Incomplete data leads to inaccurate audit trails.
  • Cross-reference events across scopes (account, org, project) for a complete picture. Do not skip scope levels.
  • For compliance reports, verify every claim against actual audit data. Do not infer or assume activity that is not in the logs.

Troubleshooting

No Events Found
  1. Start with a broader time range and no filters
  2. Verify the org_id and project_id scope -- account-level events require no org/project filter
  3. Remove search_term to confirm events exist, then re-add filters
Missing User Activity
  1. Check both email and username formats for the user
  2. Service account activity may appear under a different principal name
  3. API key usage may not show as the human user
Incomplete Audit Trail
  1. Paginate through all results -- check if size returned equals the size requested (more pages likely)
  2. Account-level events are separate from org/project events -- query at the right scope
  3. Some event types may require specific permissions to view

© harness, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/audit-report of harness/harness-skills.

  • SKILL.md
  • references/report-templates.md

Open the folder on GitHubat commit c25faee

Compare with similar skills

Audit Report next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Audit Report compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Audit Report this skillharness/harness-skills115—~1.3kAutomated safety check: PassApache-2.0
Cis ControlsSushegaad/Claude-Skills-Governance-Risk-and-Compliance9421 repos~4.2kAutomated safety check: PassMIT
Security Compliancesangrokjung/claude-forge8502 repos~7.2kAutomated safety check: PassMIT
Ciso Advisoralirezarezvani/claude-skills28k1 repos~1.8kAutomated safety check: PassMIT
ComplianceRightNow-AI/openfang18k—~921Automated safety check: PassApache-2.0
Eks Securityaws-samples/appmod-blueprints113—~4.7kAutomated safety check: PassMIT-0

Similar skills

  • Cis Controls

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert CIS Controls v8 (CIS Top 18) advisor — implementation group scoping (IG1/IG2/IG3), control gap assessments, safeguard-level guidance, asset inventory, software inventory, data protection…

    942 GitHub starsUsed in 1 repo~4.2k tokens
    Legal & ComplianceAuto-check passed
  • Security Compliance

    sangrokjung/claude-forge

    Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and…

    850 GitHub starsUsed in 2 repos~7.2k tokens
    Legal & ComplianceAuto-check passed
  • Ciso Advisor

    alirezarezvani/claude-skills

    Security leadership for growth-stage companies. An agent skill from alirezarezvani/claude-skills.

    28k GitHub starsUsed in 1 repo~1.8k tokens
    Legal & ComplianceAuto-check passed
  • Compliance

    RightNow-AI/openfang

    Compliance expert for SOC 2, GDPR, HIPAA, PCI-DSS, and security frameworks

    18k GitHub stars~921 tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check passed
  • Eks Security

    aws-samples/appmod-blueprints

    Official

    A skill your agent uses whenever someone needs security or compliance guidance for Amazon EKS — phrased as "CIS Benchmark for EKS", "HIPAA / PCI-DSS / FedRAMP / SOC 2 / GDPR on EKS", "harden my EKS…

    113 GitHub stars~4.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Policy Opa

    AgentSecOps/SecOpsAgentKit

    Policy-as-code enforcement and compliance validation using Open Policy Agent (OPA).

    220 GitHub starsUsed in 1 repo~3.5k tokens
    Legal & ComplianceAuto-check passed

More from harness/harness-skills

All 24 skills in this repo
  • Chaos Dr Test

    harness/harness-skills

    A skill your agent uses when working with Chaos Engineering steps inside a Harness pipeline.

    115 GitHub stars~2.6k tokensUpdated yesterday
    Auto-check passed
  • Chaos Experiment

    harness/harness-skills

    A skill your agent uses when the user asks to create, edit, update, design, or configure a Harness Chaos Experiment — including faults, probes, actions, experiment YAML, fault injection, pod-delete…

    115 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Cleanup Feature Flags

    harness/harness-skills

    Remove a launched Harness FME feature flag from application code, keeping the treatment FME serves today, and open a pull request.

    115 GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • Configure Repo Scan

    harness/harness-skills

    Configure code scanning in Harness pipelines using STO security scanners.

    115 GitHub stars~2.2k tokensUpdated yesterday
    Auto-check passed
  • Create Agent Template

    harness/harness-skills

    Generate Harness Agent Template files for AI-powered automation agents.

    115 GitHub stars~2.2k tokensUpdated yesterday
    Auto-check passed
  • Create Metric

    harness/harness-skills

    Create a Harness FME metric: helps decide what to measure, suggests candidate metrics from application code, resolves traffic type and event type IDs, drafts the payload, then creates.

    115 GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed

Questions about Audit Report

What does Audit Report do?

Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools. Audit Report is an agent skill from harness/harness-skills. Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.

When should I use Audit Report?

Audit Report fits situations like: asked to audit activity; generate compliance reports; investigate security incidents; review user actions.

How do I install Audit Report in Claude Code?

Run `npx skills add harness/harness-skills --skill audit-report -a claude-code`. Or copy the skill folder (skills/audit-report in harness/harness-skills) into .claude/skills/audit-report in your project. Claude Code loads it when a task matches its description.

How do I install Audit Report in Codex?

Run `npx skills add harness/harness-skills --skill audit-report -a codex`. Or copy the skill folder (skills/audit-report in harness/harness-skills) into .agents/skills/audit-report in your project. Codex loads it when a task matches its description.

Can I use Audit Report in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add harness/harness-skills --skill audit-report -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-report, .gemini/skills/audit-report, .github/skills/audit-report and .opencode/skills/audit-report in your project.

What does Audit Report need to run?

SKILL.md names no scripts, command-line tools or credentials: Audit Report is instructions for the agent only. Compatibility (from SKILL.md): Requires Harness MCP v2 server (harness-mcp-v2).

Does Audit Report access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Audit Report safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Audit Report use?

Audit Report is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Audit Report use?

About 1.3k tokens (SKILL.md is roughly 5.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 794 tokens, read only when the agent opens those files.

What are the alternatives to Audit Report?

Skills that share tags, products or a category with Audit Report: Cis Controls (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 942 stars), Security Compliance (sangrokjung/claude-forge, 850 stars), Ciso Advisor (alirezarezvani/claude-skills, 28k stars) and Compliance (RightNow-AI/openfang, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Audit Report?

harness (a GitHub organization) maintains it in harness/harness-skills, which has 115 GitHub stars. The repository holds 24 skills in this directory. The repository was last updated on October 6, 2026.

Source: harness/harness-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.