Agent skill

Create Policy

by harness in harness/harness-skills

Create OPA governance policies for Harness via MCP. An agent skill from harness/harness-skills.

Apache-2.0Auto-check passedDevOps & Cloud

Install Create Policy

skills CLI
$ npx skills add harness/harness-skills --skill create-policy -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install harness/harness-skills create-policy --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/harness/harness-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/create-policy .claude/skills/create-policy && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
create-policy
GitHub stars
115
Token cost
~1.9k tokens
SKILL.md length
636 words
Files
19 (incl. references)
Skills in repo
64
Repo updated
First seen
Licence
Apache-2.0

At a glance

Create OPA governance policies for Harness via MCP. An agent skill from harness/harness-skills.

  • Works in 3 steps: Identify Policy Requirements → Create the Policy → Verify Compliance Results
  • Asked to create
  • SKILL.md covers Instructions, Common Policy Patterns, Related Resource Types and Rego Policy Reference Files, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Create Policy is an agent skill from harness/harness-skills. Create OPA governance policies for Harness via MCP. Define policies that enforce compliance rules on pipelines, services, environments, feature flags, artifacts, code repositories, templates, SBOM, security tests, Terraform, GitOps, connectors, secrets, and more. Use when asked to create, write, fix, or explain an OPA policy, Rego rule, deny rule, governance policy, compliance rule, or policy-as-code for any Harness entity. Trigger phrases: create policy, OPA policy, governance policy, compliance rule, rego…

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 19 other files, including reference files (for example `references/advanced-patterns.md`, `references/entity-code-repository.md` and `references/entity-connector.md`). Compatibility notes: Requires Harness MCP v2 server (harness-mcp-v2)

It sits in DevOps & Cloud, covering Supply chain security, Infrastructure as code and GitOps. It works with Model Context Protocol and Terraform. The repository describes itself as: A collection of structured AI agent skills that enable Claude Code, Cursor, GitHub Copilot, and other AI coding assistants to create, operate, debug, and govern Harness CI/CD… The licence is Apache-2.0.

When your agent uses it

  • Asked to create
  • Explain an OPA policy
  • Governance policy
  • Compliance rule

Example prompts

  • “/create-policy”

Requirements

  • Compatibility (from SKILL.md): Requires Harness MCP v2 server (harness-mcp-v2)

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Identify Policy Requirements
  2. Create the Policy
  3. Verify Compliance Results

What it can do on your machine

Read from SKILL.md and the folder at commit c25faee. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are rego).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires Harness MCP v2 server (harness-mcp-v2)

    From compatibility in the SKILL.md frontmatter.

Context cost

Create Policy loads about 1.9k tokens when it runs, and up to ~43k if it reads all its reference files. Until then it costs about 151 tokens; SKILL.md has 636 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~151
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~43k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from harness/harness-skills at commit c25faee, republished under its Apache-2.0 licence (© harness). 636 words, ~1,948 tokens.

Download SKILL.mdSave it as .claude/skills/create-policy/SKILL.md (or your agent's skills folder). This skill also uses 18 other files; get the full folder from GitHub.
name
create-policy
description
Create OPA governance policies for Harness via MCP. Define policies that enforce compliance rules on pipelines, services, environments, feature flags, artifacts, code repositories, templates, SBOM, security tests, Terraform, GitOps, connectors, secrets, and more. Use when asked to create, write, fix, or explain an OPA policy, Rego rule, deny rule, governance policy, compliance rule, or policy-as-code for any Harness entity. Trigger phrases: create policy, OPA policy, governance policy, compliance rule, rego policy, deny rule, enforce policy, security policy, supply chain governance.
compatibility
Requires Harness MCP v2 server (harness-mcp-v2)
metadata.author
Harness
metadata.version
1.0.0
metadata.mcp-server
harness-mcp-v2
license
Apache-2.0

Create Policy

Create OPA governance policies for Harness Software Supply Chain Assurance (SCS) via MCP.

Instructions

Step 1: Identify Policy Requirements

Determine what the policy should enforce:

  • What entity type is the policy targeting? (pipeline, service, environment, feature flag, etc.)
  • What is the enforcement action (warn, deny)?
  • What scope should the policy apply to?
  • What action triggers the policy? (onrun, onsave, onstep, etc.)

For writing Rego policies, consult references/rego-writing-guide.md for the complete Rego writing rules, entity types, package names, and common patterns. For entity-specific schemas and examples, see the entity reference files listed in that guide.

Step 2: Create the Policy
Call MCP tool: harness_create
Parameters:
  resource_type: "policy"
  org_id: "<organization>"
  project_id: "<project>"
  body: <policy definition>

OPA policies are managed under the governance toolset — resource_type: "policy" supports full CRUD (list, get, create, update, delete).

Step 3: Verify Compliance Results

After a policy is created, check compliance status on artifacts or repositories:

Call MCP tool: harness_list
Parameters:
  resource_type: "scs_compliance_result"
  org_id: "<organization>"
  project_id: "<project>"

Common Policy Patterns

Require SBOM Generation

Enforce that all artifacts have an SBOM before deployment:

rego
package harness.artifact

deny[msg] {
  not input.artifact.sbom
  msg := "Artifact must have an SBOM before deployment"
}
Block Critical Vulnerabilities

Deny deployment of artifacts with critical CVEs:

rego
package harness.artifact

deny[msg] {
  vuln := input.artifact.vulnerabilities[_]
  vuln.severity == "CRITICAL"
  msg := sprintf("Critical vulnerability %s found in artifact", [vuln.cve_id])
}
Enforce Approved Base Images

Restrict container images to approved base images:

rego
package harness.artifact

approved_bases := {"alpine", "distroless", "ubuntu"}

deny[msg] {
  not approved_bases[input.artifact.base_image]
  msg := sprintf("Base image '%s' is not in the approved list", [input.artifact.base_image])
}
Require Signed Artifacts

Enforce artifact signing before deployment:

rego
package harness.artifact

deny[msg] {
  not input.artifact.signed
  msg := "Artifact must be signed before deployment"
}
Resource TypeOperationsDescription
policylist, get, create, update, deleteOPA governance policies (governance toolset)
policy_setlist, get, create, update, deleteGroup policies with enforcement actions
policy_evaluationlist, getView policy evaluation results
scs_compliance_resultlistCheck SCS policy compliance status
artifact_securitylist, getView artifact security posture
code_repo_securitylist, getView repository security posture
scs_chain_of_custodygetVerify artifact provenance

Rego Policy Reference Files

For writing Rego policies for any Harness entity, consult these reference files:

Show full SKILL.md (234 more words)Show less

Examples

  • "Create a policy to block critical CVEs" -- Create OPA deny rule for critical severity
  • "Enforce SBOM generation for all artifacts" -- Create policy requiring SBOM presence
  • "Only allow approved base images" -- Create policy with allowed base image list
  • "Require artifact signing before production" -- Create policy checking signature status
  • "Require approval before production deployments" -- Pipeline policy with Approval stage check
  • "Enforce disallowPipelineExecutor on approval steps" -- Pipeline walk-based step check
  • "Block Terraform plans exceeding $100/month" -- Terraform plan cost policy
  • "Require feature flag descriptions" -- FME feature flag onsave policy
  • "Prevent GitOps deployments to kube-system" -- GitOps namespace restriction
  • "Check which artifacts violate our policies" -- List scs_compliance_result

Performance Notes

  • Validate Rego syntax before submitting. Common issues: missing package declaration, deny rules without msg return.
  • Ensure the policy package name follows package harness.<domain> convention.
  • Test policy logic mentally against expected inputs before creating.

Troubleshooting

Policy Not Enforcing
  • Verify the policy was created successfully (list via resource_type: "policy")
  • Policies must be attached to a policy_set with an enforcement action (warn/deny) before they fire
  • Check that the policy scope matches the target artifacts/repositories
  • Use scs_compliance_result or policy_evaluation to verify the policy is being evaluated
Policy Syntax Errors
  • OPA policies use Rego language -- validate syntax before submitting
  • Package names should follow package harness.<domain> convention
  • Deny rules must return a msg string explaining the violation
Limitations
  • Policies apply within the project scope where they are created
  • Attach policies to a policy_set to activate enforcement

© harness, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 18 other files (references) in skills/create-policy of harness/harness-skills.

  • SKILL.md
  • references/advanced-patterns.md
  • references/entity-code-repository.md
  • references/entity-connector.md
  • references/entity-database.md
  • references/entity-feature-flag.md
  • references/entity-gitops.md
  • references/entity-override.md
  • references/entity-pipeline.md
  • references/entity-sbom.md
  • references/entity-secret.md
  • references/entity-security-tests.md
  • references/entity-service-env-infra.md
  • references/entity-template.md
  • references/entity-terraform.md
  • references/entity-upstream-firewall.md
  • references/entity-variable.md
  • references/quality-tests.md
  • references/rego-writing-guide.md

Open the folder on GitHubat commit c25faee

Compare with similar skills

Create Policy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Create Policy compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Create Policy this skillharness/harness-skills115—~1.9kAutomated safety check: PassApache-2.0
Terravision Cloud Diagramspatrickchugh/terravision1.6k—~5.6kAutomated safety check: NotesAGPL-3.0-only
Infra Syncagentic-community/mcp-gateway-registry962—~2.7kAutomated safety check: PassApache-2.0
Eks Best Practicesaws-samples/appmod-blueprints113—~5kAutomated safety check: PassMIT-0
Gitops Knowledgefluxcd/agent-skills230—~3.8kAutomated safety check: PassApache-2.0
AWS Sst Developmentzxkane/aws-skills367—~2.7kAutomated safety check: WarnMIT

Similar skills

  • Terravision Cloud Diagrams

    patrickchugh/terravision

    Draw cloud architecture diagrams for AWS, Azure or GCP with the official provider icon sets, using TerraVision.

    1.6k GitHub stars~5.6k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Infra Sync

    agentic-community/mcp-gateway-registry

    Keep Terraform and CDK infrastructure in sync. An agent skill from agentic-community/mcp-gateway-registry.

    962 GitHub stars~2.7k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Eks Best Practices

    aws-samples/appmod-blueprints

    Official

    Advisory guidance for Amazon EKS architecture and configuration decisions — compute strategy, networking, security, reliability, cost, autoscaling, observability, multi-tenancy, and upgrade planning.

    113 GitHub stars~5k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Gitops Knowledge

    fluxcd/agent-skills

    Flux CD and Flux Operator expert — answers questions and generates schema-validated YAML for all Flux CRDs (not repo auditing or live cluster debugging).

    230 GitHub stars~3.8k tokensUpdated 5 days ago
    DevOps & CloudAuto-check passed
  • AWS Sst Development

    zxkane/aws-skills

    SST v4 (Ion) expert for managing AWS resources as code with the Pulumi-backed framework.

    367 GitHub stars~2.7k tokensUpdated 3 mo ago
    DevOps & CloudAuto-check: warnings
  • Sca Trivy

    AgentSecOps/SecOpsAgentKit

    Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…

    219 GitHub starsUsed in 2 repos~3.7k tokens
    SecurityAuto-check passed

More from harness/harness-skills

All 64 skills in this repo
  • Audit Report

    harness/harness-skills

    Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.

    115 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • Chaos Dr Test

    harness/harness-skills

    A skill your agent uses when working with Chaos Engineering steps inside a Harness pipeline.

    115 GitHub stars~2.6k tokensUpdated yesterday
    Auto-check passed
  • Chaos Experiment

    harness/harness-skills

    A skill your agent uses when the user asks to create, edit, update, design, or configure a Harness Chaos Experiment — including faults, probes, actions, experiment YAML, fault injection, pod-delete…

    115 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Cleanup Feature Flags

    harness/harness-skills

    Remove a launched Harness FME feature flag from application code, keeping the treatment FME serves today, and open a pull request.

    115 GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • Configure Repo Scan

    harness/harness-skills

    Configure code scanning in Harness pipelines using STO security scanners.

    115 GitHub stars~2.2k tokensUpdated yesterday
    Auto-check passed
  • Create Agent Template

    harness/harness-skills

    Generate Harness Agent Template files for AI-powered automation agents.

    115 GitHub stars~2.2k tokensUpdated yesterday
    Auto-check passed

Questions about Create Policy

What does Create Policy do?

Create OPA governance policies for Harness via MCP. An agent skill from harness/harness-skills. Create Policy is an agent skill from harness/harness-skills. Create OPA governance policies for Harness via MCP.

When should I use Create Policy?

Create Policy fits situations like: asked to create; explain an OPA policy; governance policy; compliance rule.

How do I install Create Policy in Claude Code?

Run `npx skills add harness/harness-skills --skill create-policy -a claude-code`. Or copy the skill folder (skills/create-policy in harness/harness-skills) into .claude/skills/create-policy in your project. Claude Code loads it when a task matches its description.

How do I install Create Policy in Codex?

Run `npx skills add harness/harness-skills --skill create-policy -a codex`. Or copy the skill folder (skills/create-policy in harness/harness-skills) into .agents/skills/create-policy in your project. Codex loads it when a task matches its description.

Can I use Create Policy in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add harness/harness-skills --skill create-policy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/create-policy, .gemini/skills/create-policy, .github/skills/create-policy and .opencode/skills/create-policy in your project.

What does Create Policy need to run?

SKILL.md names no scripts, command-line tools or credentials: Create Policy is instructions for the agent only. Compatibility (from SKILL.md): Requires Harness MCP v2 server (harness-mcp-v2).

Does Create Policy access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Create Policy safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Create Policy use?

Create Policy is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Create Policy use?

About 1.9k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 41k tokens, read only when the agent opens those files.

What are the alternatives to Create Policy?

Skills that share tags, products or a category with Create Policy: Terravision Cloud Diagrams (patrickchugh/terravision, 1.6k stars), Infra Sync (agentic-community/mcp-gateway-registry, 962 stars), Eks Best Practices (aws-samples/appmod-blueprints, 113 stars) and Gitops Knowledge (fluxcd/agent-skills, 230 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Create Policy?

harness (a GitHub organization) maintains it in harness/harness-skills, which has 115 GitHub stars. The repository holds 64 skills in this directory. The repository was last updated on October 6, 2026.

Source: harness/harness-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.