Agent skill

Configure Repo Scan

by harness in harness/harness-skills

Configure code scanning in Harness pipelines using STO security scanners.

Apache-2.0Auto-check passedSecurity

Install Configure Repo Scan

skills CLI
$ npx skills add harness/harness-skills --skill configure-repo-scan -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install harness/harness-skills configure-repo-scan --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/harness/harness-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/configure-repo-scan .claude/skills/configure-repo-scan && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
configure-repo-scan
GitHub stars
115
Token cost
~2.2k tokens
SKILL.md length
779 words
Files
2 (incl. references)
Skills in repo
24
Repo updated
First seen
Licence
Apache-2.0

At a glance

Configure code scanning in Harness pipelines using STO security scanners.

  • Works in 8 steps: Establish Scope and Pipeline Context → Extract Repository Connector from Pipeline → Analyze Pipeline Structure → …
  • Asked to add code scanning
  • SKILL.md covers Instructions, Examples, Performance Notes and Troubleshooting
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Configure Repo Scan is an agent skill from harness/harness-skills. Configure code scanning in Harness pipelines using STO security scanners. Helps identify where to inject SAST/SCA scanning steps into existing pipelines, recommends appropriate scanners, and configures them with proper connector references. Use when asked to add code scanning, configure security scans, set up SAST/SCA, integrate vulnerability scanning, or add security checks to a pipeline. Trigger phrases: add code scanner, configure repo scan, set up SAST, add security scan, configure vulnerability scanning…

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/scanner-types.md`). Compatibility notes: Requires Harness MCP v2 server (harness-mcp-v2)

It sits in Security, covering Static analysis and SAST, Vulnerability scanning and Security review. The repository describes itself as: A collection of structured AI agent skills that enable Claude Code, Cursor, GitHub Copilot, and other AI coding assistants to create, operate, debug, and govern Harness CI/CD… The licence is Apache-2.0.

When your agent uses it

  • Asked to add code scanning
  • Configure security scans
  • Set up SAST/SCA
  • Integrate vulnerability scanning

Example prompts

  • “/configure-repo-scan”

Requirements

  • Python 3
  • Compatibility (from SKILL.md): Requires Harness MCP v2 server (harness-mcp-v2)

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Establish Scope and Pipeline Context
  2. Extract Repository Connector from Pipeline
  3. Analyze Pipeline Structure
  4. Recommend Scanner Type
  5. Generate Scanner Step Configuration
  6. Insert Step into Pipeline YAML
  7. Update Pipeline via MCP
  8. Provide Summary and Next Steps

What it can do on your machine

Read from SKILL.md and the folder at commit c25faee. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are yaml).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires Harness MCP v2 server (harness-mcp-v2)

    From compatibility in the SKILL.md frontmatter.

Context cost

Configure Repo Scan loads about 2.2k tokens when it runs, and up to ~4.6k if it reads all its reference files. Until then it costs about 138 tokens; SKILL.md has 779 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~138
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from harness/harness-skills at commit c25faee, republished under its Apache-2.0 licence (© harness). 779 words, ~2,247 tokens.

Download SKILL.mdSave it as .claude/skills/configure-repo-scan/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
configure-repo-scan
description
Configure code scanning in Harness pipelines using STO security scanners. Helps identify where to inject SAST/SCA scanning steps into existing pipelines, recommends appropriate scanners, and configures them with proper connector references. Use when asked to add code scanning, configure security scans, set up SAST/SCA, integrate vulnerability scanning, or add security checks to a pipeline. Trigger phrases: add code scanner, configure repo scan, set up SAST, add security scan, configure vulnerability scanning, integrate scanner.
compatibility
Requires Harness MCP v2 server (harness-mcp-v2)
metadata.author
Harness
metadata.version
1.0.0
metadata.mcp-server
harness-mcp-v2
license
Apache-2.0

Configure Repo Scan

Add code scanning steps to existing Harness pipelines using STO security scanners.

Instructions

Step 1: Establish Scope and Pipeline Context

Ask the user for the organization, project, and pipeline identifier if not already known. This skill only works with existing pipelines.

Once you have the identifiers, fetch the pipeline definition:

Call MCP tool: harness_get
Parameters:
  resource_type: "pipeline"
  resource_id: "<pipeline_identifier>"
  org_id: "<organization>"
  project_id: "<project>"
Step 2: Extract Repository Connector from Pipeline

Parse the pipeline YAML from Step 1 to automatically identify the repository connector used in the pipeline.

Look for the connector reference in the pipeline structure:

  • For v0 pipelines: Check pipeline.properties.ci.codebase.connectorRef
  • For v1 pipelines: Check the codebase connector in the pipeline configuration

If no connector is found in the pipeline, inform the user that the pipeline does not have a codebase configuration and cannot proceed with repo scanning.

Step 3: Analyze Pipeline Structure

Parse the pipeline YAML from Step 1 to identify:

  • All stages (CI, Deployment, Approval, Custom)
  • All steps within each stage
  • Existing security scanning steps (if any)

Present a structured view to the user showing:

Pipeline: <name>

Stage 1: <stage_name> (type: <stage_type>)
  - Step 1: <step_name> (type: <step_type>)
  - Step 2: <step_name> (type: <step_type>)
  ...

Stage 2: <stage_name> (type: <stage_type>)
  - Step 1: <step_name> (type: <step_type>)
  ...

Ask the user where they would like to insert the code scanner step:

  • "Before which step?" or "After which step?" or "At the end of which stage?"
  • Provide suggestions (e.g., "I recommend adding it after the build step but before deployment")
Step 4: Recommend Scanner Type

Present the available SAST scanners supported in Harness STO:

Available SAST Scanners:

  • Harness Code (default - native Harness scanner)
  • Bandit (open-source, Python)
  • Black Duck (by Synopsys)
  • Brakeman (open-source, Ruby)
  • Checkmarx
  • Checkmarx One
  • Coverity (open-source)
  • CodeQL
  • FOSSA
  • GitHub Advanced Security
  • Mend (formerly WhiteSource)
  • Semgrep (open-source)
  • Snyk
  • SonarQube
  • Veracode
  • Wiz

Default recommendation: Use Harness Code as the native Harness SAST scanner. It provides integrated security scanning with minimal configuration and seamless integration with Harness STO.

Ask the user which scanner they prefer. If they don't specify, use Harness Code as the default.

Step 5: Generate Scanner Step Configuration

Based on the scanner choice and connector from Step 2, generate the appropriate step YAML. The scanner step should be a native Harness STO step, not a Run step.

For Harness Code (default):

yaml
- step:
    identifier: harness_code_scan
    name: Harness Code Scan
    type: HarnessSAST
    spec:
      mode: orchestration
      config: sast_sca
      target:
        type: repository
        detection: auto
      advanced:
        log:
          level: info

For Bandit (Python):

yaml
- step:
    identifier: bandit_scan
    name: Bandit SAST
    type: Bandit
    spec:
      mode: orchestration
      config: default
      target:
        type: repository
        detection: auto
      advanced:
        log:
          level: info

For Semgrep:

yaml
- step:
    identifier: semgrep_scan
    name: Semgrep SAST
    type: Semgrep
    spec:
      mode: orchestration
      config: default
      target:
        type: repository
        detection: auto
      advanced:
        log:
          level: info

For other scanners: Reference references/scanner-types.md for scanner-specific configuration.

Step 6: Insert Step into Pipeline YAML

Insert the generated scanner step YAML at the location chosen in Step 3. Ensure proper indentation and structure.

Key rules:

  • Scanner steps should be added to CI stages (type: CI), not Deployment or Approval stages
  • Scanner steps should typically run after code checkout but before deployment
  • If the pipeline has a cloneCodebase: true setting, the scanner will have access to the source code
  • The scanner step should be added to the execution.steps array within the chosen stage

Create the updated pipeline YAML with the scanner step inserted.

Step 7: Update Pipeline via MCP

Update the pipeline with the new scanner step:

Call MCP tool: harness_update
Parameters:
  resource_type: "pipeline"
  resource_id: "<pipeline_identifier>"
  org_id: "<organization>"
  project_id: "<project>"
  body: { yamlPipeline: "<updated pipeline YAML string>" }
Show full SKILL.md (317 more words)Show less
Step 8: Provide Summary and Next Steps

Report the results to the user:

## Code Scanner Configured

**Pipeline:** <pipeline_name>
**Scanner:** <scanner_type>
**Location:** Stage "<stage_name>", <position description>
**Connector:** <connector_name>

**Pipeline URL:** https://app.harness.io/ng/account/<account_id>/module/ci/orgs/<org_id>/projects/<project_id>/pipelines/<pipeline_id>/pipeline-studio/

**Note:** The scanner step has been configured with default settings. You can review and modify the configuration in the pipeline studio if you need to customize scan behavior, add exclusions, or adjust other parameters.

### Next Steps
1. Run the pipeline to verify the scanner step executes successfully
2. View scan results in the Security Tests tab of the execution
3. Configure exemptions for false positives via `/security-report` skill
4. Set up policies to fail pipelines on critical vulnerabilities via `/create-policy` skill

Examples

Add scanner to existing pipeline
/configure-repo-scan
I want to add code scanning to my backend-api pipeline in the platform project
Configure SAST for Python project
/configure-repo-scan
Set up SAST scanning for my Python service. Use Bandit and add it after the test step.
Add Harness Code scan to CI pipeline
/configure-repo-scan
Add Harness Code scanner to my CI pipeline. Scan after build but before pushing to registry.

Performance Notes

  • Always verify the pipeline exists before attempting to modify it
  • Automatically extract the repository connector from the pipeline configuration instead of asking the user
  • Parse the complete pipeline structure to provide accurate insertion point recommendations
  • Use native STO scanner steps (Harness Code, Bandit, Semgrep, etc.) instead of Run steps with scanner CLI commands
  • Default to Harness Code scanner unless the user has specific scanner preferences
  • Ensure the scanner step is added to a CI stage with cloneCodebase: true so source code is available
  • This skill only works with existing pipelines; do not offer to create new pipelines

Troubleshooting

Pipeline Not Found
  • Verify org_id and project_id are correct
  • Check RBAC permissions for pipeline access
  • Confirm the pipeline exists with harness_list (resource_type: "pipeline")
  • Inform the user that this skill only works with existing pipelines
Connector Not Found in Pipeline
  • Verify the pipeline has a codebase configuration with a connector reference
  • Check pipeline.properties.ci.codebase.connectorRef for v0 pipelines
  • Inform the user that the pipeline must have a codebase connector configured for repo scanning
Scanner Step Fails
  • Verify cloneCodebase: true is set on the CI stage
  • Check that the connector has proper authentication configured
  • Ensure the scanner image is accessible (registry permissions)
  • Review execution logs via harness_diagnose for specific scanner errors
Pipeline Update Validation Errors
  • Verify YAML indentation is correct (use 2 spaces)
  • Ensure step identifier follows pattern ^[a-zA-Z_][0-9a-zA-Z_]{0,127}$
  • Check that the step is added to a valid stage with proper spec.execution.steps structure
  • Confirm the scanner type is a valid Harness STO step type
No Security Results After Scan
  • Verify STO module is enabled for the account
  • Check scan output logs for errors or warnings
  • Confirm scanner target configuration matches repository structure
  • Ensure scanner has proper permissions to access dependencies

© harness, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/configure-repo-scan of harness/harness-skills.

  • SKILL.md
  • references/scanner-types.md

Open the folder on GitHubat commit c25faee

Compare with similar skills

Configure Repo Scan next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Configure Repo Scan compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Configure Repo Scan this skillharness/harness-skills115—~2.2kAutomated safety check: PassApache-2.0
CodeCrucible Security Scansblock/codecrucible117—~1.2kAutomated safety check: PassApache-2.0
Warden Scanjeremylongshore/tons-of-skills-marketplace2.8k—~750Automated safety check: NotesMIT
CodeQL Security Scantrailofbits/skills7.5k—~4.6kAutomated safety check: NotesCC-BY-SA-4.0
Pyspector Security AuditParzivalHack/PySpector151—~3.5kAutomated safety check: NotesApache-2.0
CSO Security Auditgarrytan/gstack136k—~4.5kAutomated safety check: PassMIT

Similar skills

  • CodeCrucible Security Scans

    block/codecrucible

    Official

    Runs the codecrucible CLI for LLM-backed security scans of a repository, checks scope and cost first with a dry run, and reads the SARIF results.

    117 GitHub stars~1.2k tokensUpdated 4 days ago
    SecurityAuto-check passed
  • Warden Scan

    jeremylongshore/tons-of-skills-marketplace

    Automated SAST + dependency vulnerability scan. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~750 tokensUpdated yesterday
    SecurityAuto-check: notes
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.5k GitHub stars~4.6k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Pyspector Security Audit

    ParzivalHack/PySpector

    Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner.

    151 GitHub stars~3.5k tokensUpdated yesterday
    SecurityAuto-check: notes
  • CSO Security Audit

    garrytan/gstack

    Runs an evidence-first security audit of a codebase through gstack's trusted launcher, with static findings by default and isolated reproduction when enabled.

    136k GitHub stars~4.5k tokensUpdated today
    SecurityAuto-check passed
  • Cyber Neo

    Hainrixz/cyber-neo

    Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.

    283 GitHub stars~5.9k tokensUpdated 2 mo ago
    SecurityAuto-check: warnings

More from harness/harness-skills

All 24 skills in this repo
  • Audit Report

    harness/harness-skills

    Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.

    115 GitHub stars~1.3k tokensUpdated 4 days ago
    Auto-check passed
  • Chaos Dr Test

    harness/harness-skills

    A skill your agent uses when working with Chaos Engineering steps inside a Harness pipeline.

    115 GitHub stars~2.6k tokensUpdated 4 days ago
    Auto-check passed
  • Chaos Experiment

    harness/harness-skills

    A skill your agent uses when the user asks to create, edit, update, design, or configure a Harness Chaos Experiment — including faults, probes, actions, experiment YAML, fault injection, pod-delete…

    115 GitHub stars~1.6k tokensUpdated 4 days ago
    Auto-check passed
  • Cleanup Feature Flags

    harness/harness-skills

    Remove a launched Harness FME feature flag from application code, keeping the treatment FME serves today, and open a pull request.

    115 GitHub stars~2.4k tokensUpdated 4 days ago
    Auto-check passed
  • Create Agent Template

    harness/harness-skills

    Generate Harness Agent Template files for AI-powered automation agents.

    115 GitHub stars~2.2k tokensUpdated 4 days ago
    Auto-check passed
  • Create Metric

    harness/harness-skills

    Create a Harness FME metric: helps decide what to measure, suggests candidate metrics from application code, resolves traffic type and event type IDs, drafts the payload, then creates.

    115 GitHub stars~3.4k tokensUpdated 4 days ago
    Auto-check passed

Categories

Questions about Configure Repo Scan

What does Configure Repo Scan do?

Configure code scanning in Harness pipelines using STO security scanners. Configure Repo Scan is an agent skill from harness/harness-skills. Configure code scanning in Harness pipelines using STO security scanners.

When should I use Configure Repo Scan?

Configure Repo Scan fits situations like: asked to add code scanning; configure security scans; set up SAST/SCA; integrate vulnerability scanning.

How do I install Configure Repo Scan in Claude Code?

Run `npx skills add harness/harness-skills --skill configure-repo-scan -a claude-code`. Or copy the skill folder (skills/configure-repo-scan in harness/harness-skills) into .claude/skills/configure-repo-scan in your project. Claude Code loads it when a task matches its description.

How do I install Configure Repo Scan in Codex?

Run `npx skills add harness/harness-skills --skill configure-repo-scan -a codex`. Or copy the skill folder (skills/configure-repo-scan in harness/harness-skills) into .agents/skills/configure-repo-scan in your project. Codex loads it when a task matches its description.

Can I use Configure Repo Scan in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add harness/harness-skills --skill configure-repo-scan -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/configure-repo-scan, .gemini/skills/configure-repo-scan, .github/skills/configure-repo-scan and .opencode/skills/configure-repo-scan in your project.

What does Configure Repo Scan need to run?

SKILL.md names no scripts, command-line tools or credentials: Configure Repo Scan is instructions for the agent only. Our summary lists: Python 3. Compatibility (from SKILL.md): Requires Harness MCP v2 server (harness-mcp-v2).

Does Configure Repo Scan access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Configure Repo Scan safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Configure Repo Scan use?

Configure Repo Scan is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Configure Repo Scan use?

About 2.2k tokens (SKILL.md is roughly 9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.3k tokens, read only when the agent opens those files.

What are the alternatives to Configure Repo Scan?

Skills that share tags, products or a category with Configure Repo Scan: CodeCrucible Security Scans (block/codecrucible, 117 stars), Warden Scan (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), CodeQL Security Scan (trailofbits/skills, 7.5k stars) and Pyspector Security Audit (ParzivalHack/PySpector, 151 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Configure Repo Scan?

harness (a GitHub organization) maintains it in harness/harness-skills, which has 115 GitHub stars. The repository holds 24 skills in this directory. The repository was last updated on October 6, 2026.

Source: harness/harness-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.