Agent skill

Enforce Sbom

by harness in harness/harness-skills

Add an SBOM Policy Enforcement (SscaEnforcement / CdSscaEnforcement) step to an existing Harness pipeline to verify SBOM attestations and apply OPA SBOM policy sets.

Apache-2.0Auto-check passedSecurity

Install Enforce Sbom

skills CLI
$ npx skills add harness/harness-skills --skill enforce-sbom -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install harness/harness-skills enforce-sbom --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/harness/harness-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/enforce-sbom .claude/skills/enforce-sbom && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
enforce-sbom
GitHub stars
115
Token cost
~3.9k tokens
SKILL.md length
1,400 words
Files
3 (incl. references)
Skills in repo
24
Repo updated
First seen
Licence
Apache-2.0

At a glance

Add an SBOM Policy Enforcement (SscaEnforcement / CdSscaEnforcement) step to an existing Harness pipeline to verify SBOM attestations and apply OPA SBOM policy sets.

  • Works in 12 steps: One question per turn — use AskQuestion… → Opening message — add SBOM Policy… → Progress breadcrumb — after pipeline fetch → …
  • Asked to enforce SBOM policies
  • SKILL.md covers Interaction model (mandatory), Instructions, Examples and Performance Notes, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Enforce Sbom is an agent skill from harness/harness-skills. Add an SBOM Policy Enforcement (SscaEnforcement / CdSscaEnforcement) step to an existing Harness pipeline to verify SBOM attestations and apply OPA SBOM policy sets. Supports CI, Security, and CD (Deployment) including CI-only pipelines — if no Deploy stage exists, add one via Phase 3b (service, environment, infra, containerized step group) then place CdSscaEnforcement before deploy. Supports container images and repositories from Artifact Registry, Third-Party registries (docker, ECR, GCR, GAR, ACR), and Git…

Its SKILL.md is about 3.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/interactive-wizard-flow.md` and `references/sbom-enforcement-step.md`). Compatibility notes: Requires Harness MCP v2 server (harness-mcp-v2)

It sits in Security, covering Supply chain security and Containers. It works with Docker and Git. The repository describes itself as: A collection of structured AI agent skills that enable Claude Code, Cursor, GitHub Copilot, and other AI coding assistants to create, operate, debug, and govern Harness CI/CD… The licence is Apache-2.0.

When your agent uses it

  • Asked to enforce SBOM policies
  • Add SBOM policy enforcement
  • Verify SBOM attestation in pipeline
  • Block non-compliant components

Example prompts

  • “/enforce-sbom”

Requirements

  • Docker
  • Compatibility (from SKILL.md): Requires Harness MCP v2 server (harness-mcp-v2)

Workflow steps

12 steps, taken from the first numbered list in SKILL.md.

  1. One question per turn — use AskQuestion when available; otherwise numbered options with (Recommended).
  2. Opening message — add SBOM Policy Enforcement to an existing pipeline; mention SBOM + policy set prerequisites.
  3. Progress breadcrumb — after pipeline fetch
  4. Record answers — running summary; do not re-ask unless the user changes direction.
  5. Fetch before configure — harness_get before placement/source questions.
  6. Show pipeline structure — list stages/steps; highlight SscaOrchestration and connectors.
  7. Infer source from orchestration — when one SBOM generation step exists, reuse its source and image.
  8. Never guess image tags — default to orchestration step image; ask if ambiguous.
  9. Confirm before write — summary + harness_update only after user confirms.
  10. Stop after update — after successful harness_update, provide a configuration summary and
  11. CD placement without an existing Deploy stage — if the user chooses CD enforcement (cd_before_deploy, add_cd_stage, or similar) on a…
  12. Never block CD on “no Deployment stage” — warn in Phase 2, then proceed via Phase 3b when the user wants CD.

What it can do on your machine

Read from SKILL.md and the folder at commit c25faee. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are yaml).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires Harness MCP v2 server (harness-mcp-v2)

    From compatibility in the SKILL.md frontmatter.

Context cost

Enforce Sbom loads about 3.9k tokens when it runs, and up to ~8.2k if it reads all its reference files. Until then it costs about 233 tokens; SKILL.md has 1,400 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~233
When it runs · the whole SKILL.md, loaded when a task matches
~3.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from harness/harness-skills at commit c25faee, republished under its Apache-2.0 licence (© harness). 1,400 words, ~3,870 tokens.

Download SKILL.mdSave it as .claude/skills/enforce-sbom/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
enforce-sbom
description
Add an SBOM Policy Enforcement (SscaEnforcement / CdSscaEnforcement) step to an existing Harness pipeline to verify SBOM attestations and apply OPA SBOM policy sets. Supports CI, Security, and CD (Deployment) including CI-only pipelines — if no Deploy stage exists, add one via Phase 3b (service, environment, infra, containerized step group) then place CdSscaEnforcement before deploy. Supports container images and repositories from Artifact Registry, Third-Party registries (docker, ECR, GCR, GAR, ACR), and Git. Matches Pipeline Studio SBOM Policy Enforcement UI. Only works with existing pipelines (may append a Deploy stage). Use when asked to enforce SBOM policies, add SBOM policy enforcement, verify SBOM attestation in pipeline, or block non-compliant components. Trigger phrases: enforce SBOM, SBOM policy enforcement, SBOM policy step, verify SBOM policy, SscaEnforcement, add policy enforcement after SBOM.
compatibility
Requires Harness MCP v2 server (harness-mcp-v2)
metadata.author
Harness
metadata.version
1.0.0
metadata.mcp-server
harness-mcp-v2
license
Apache-2.0

Enforce SBOM

Add an SBOM Policy Enforcement (SscaEnforcement / CdSscaEnforcement) step to an existing Harness pipeline. The step verifies SBOM attestations (when enabled) and evaluates SBOM OPA policy sets against the artifact's bill of materials.

This skill only works with existing pipelines — do not create standalone enforcement-only pipelines.

Prerequisites: An SBOM must already exist for the artifact (typically from SscaOrchestration via /create-sbom or SBOM ingestion). SBOM policy sets must exist (/create-policy).

Supported stages: CI, CD (Deployment), and Security — same as SBOM Orchestration. CD requires a containerized step group with container-based execution.

Guide the user through a step-by-step interactive wizard (same UX as /create-sbom):

  • Wizard: references/interactive-wizard-flow.md
  • UI ↔ YAML: references/sbom-enforcement-step.md
  • CD containerized step groups (new or existing Deploy stage): skills/create-sbom/references/cd-containerized-step-group.md

Interaction model (mandatory)

  1. One question per turn — use AskQuestion when available; otherwise numbered options with (Recommended).
  2. Opening message — add SBOM Policy Enforcement to an existing pipeline; mention SBOM + policy set prerequisites.
  3. Progress breadcrumb — after pipeline fetch: Pipeline · Placement · Source · Details · Verify · Policy · Submit
  4. Record answers — running summary; do not re-ask unless the user changes direction.
  5. Fetch before configure — harness_get before placement/source questions.
  6. Show pipeline structure — list stages/steps; highlight SscaOrchestration and connectors.
  7. Infer source from orchestration — when one SBOM generation step exists, reuse its source and image.
  8. Never guess image tags — default to orchestration step image; ask if ambiguous.
  9. Confirm before write — summary + harness_update only after user confirms.
  10. Stop after update — after successful harness_update, provide a configuration summary and point the user to /run-pipeline to execute. Do not call harness_execute, poll executions, or run harness_diagnose in this skill (same pattern as /configure-repo-scan).
  11. CD placement without an existing Deploy stage — if the user chooses CD enforcement (cd_before_deploy, add_cd_stage, or similar) on a CI-only pipeline, do not reject or force CI-only. Run Phase 3b to add a Deployment stage with a containerized step group and CdSscaEnforcement before deploy (same prerequisites as /create-sbom).
  12. Never block CD on “no Deployment stage” — warn in Phase 2, then proceed via Phase 3b when the user wants CD.

Full phase prompts: references/interactive-wizard-flow.md.


Instructions

Wizard phases (user-facing)
PhaseBreadcrumbAction
0PipelineAskQuestion: pipeline URL ready?
1PipelineCollect URL or org/project/id → harness_get
2PipelineDisplay structure; note missing SscaOrchestration
3PlacementAskQuestion: after SBOM step, CD before deploy, add CD stage, etc.
3bPlacement (CD only)If no Deployment stage: service, environment, infra, stepGroupInfra — then add stage + CdSscaEnforcement
4SourceAskQuestion: infer from pipeline or pick tile
5SourceAskQuestion: registry provider (Third-Party only)
6DetailsConnector (skip if obvious)
7DetailsImage / repo (free text; default from orchestration)
8VerifyAskQuestion: verify attestation method
9PolicyAskQuestion: policy set(s) — harness_list policy_set
10SubmitAskQuestion: confirm pipeline update

After Phase 10 confirm → insert step, harness_update, then provide summary (do not run the pipeline).

Supported stage types
Stage type (YAML)Step typePlacement notes
CISscaEnforcementAfter SscaOrchestration in the same stage
DeploymentCdSscaEnforcementContainerized step group; before deploy
SecuritySscaEnforcementAfter SBOM generation when artifact is known
CD edge case (mandatory workflow)

Use when Placement targets CD (cd_before_deploy, add_cd_stage, or an existing Deployment stage).

Phase 2 — CI-only pipeline

If there is no type: Deployment stage, note it in the structure table and add:

This pipeline has no CD Deploy stage yet. You can still enforce SBOM in CD — we will add a Deployment stage with a containerized step group and place SBOM Policy Enforcement before the deploy step.

Do not tell the user CD is invalid for this pipeline. If they chose CD in Phase 3, continue to Phase 3b.

Phase 3b — CD prerequisites (no Deploy stage yet)

Mirror /create-sbom Phase 3b — one topic per turn:

StepAction
Serviceharness_list (service) → serviceRef
Environmentharness_list (environment) → environmentRef
Infrastructureharness_list (infrastructure, params: { environment_id }); create if missing per /create-infrastructure
Step group infraK8s connector + namespace for stepGroupInfra
Deploy stepDefault K8sRollingDeploy for Kubernetes services
CI enforcementOptional: keep CI SscaEnforcement and add CD enforce_sbom_cd, or CD-only — confirm in Phase 10

Append a Deploy stage with containerized group containing CdSscaEnforcement before K8sRollingDeploy. Full YAML patterns: skills/create-sbom/references/cd-containerized-step-group.md (use CdSscaEnforcement instead of SscaOrchestration).

CD image / source: prefer <+artifact.image> from the service primary artifact; reuse connector from CI SscaOrchestration or service artifact source. Verify attestation must match the CI generation step (e.g. keyless Harness OIDC).

Step id: use enforce_sbom_cd when CI already has enforce_sbom.

After the wizard — backend steps
Check prerequisites
  1. SBOM generation — pipeline YAML contains SscaOrchestration (or user confirms SBOM was ingested).
  2. Policy sets — harness_list(resource_type="policy_set", org_id, project_id). If empty, direct user to /create-policy (SBOM entity, onstep event) before continuing.
Extract context from pipeline YAML

From SscaOrchestration (if present), copy:

  • spec.source (type + spec)
  • spec.attestation (use matching verifyAttestation when user chooses verify)
  • connector / image / registry

From build/push steps: connectorRef in BuildAndPushDockerRegistry, Run, Plugin.

Show full SKILL.md (612 more words)Show less
Generate SBOM enforcement step YAML

Use only wizard answers. Default: verify SBOM + keyless Harness OIDC + policy sets from Phase 9.

CI / Security — SscaEnforcement (Third-Party Docker):

yaml
- step:
    identifier: enforce_sbom
    name: SBOM Policy Enforcement
    type: SscaEnforcement
    spec:
      source:
        type: docker
        spec:
          connector: <docker_registry_connector>
          image: <org>/<repo>:<tag>
      verifyAttestation:
        type: cosign
        spec:
          type: keyless
          spec:
            oidcProvider: harness
      policy:
        policySets:
          - <sbom_policy_set_identifier>
    timeout: 15m

Policy sets only (UI Policy Configuration):

yaml
      policy:
        policySets:
          - sbom_license_allowlist
          - sbom_deny_critical

No verification (when user unchecks Verify SBOM):

yaml
      policy:
        policySets:
          - <sbom_policy_set_identifier>

Omit verifyAttestation.

Repository source — add overrideConnectorRef on spec (see reference doc).

CD Deployment — use CdSscaEnforcement inside a containerized stepGroup (stepGroupInfra); include spec.infrastructure matching that group (see references/sbom-enforcement-step.md and skills/create-sbom/references/cd-containerized-step-group.md). When adding a new Deploy stage, place enforcement in stepGroup.steps before the deploy step — not at top-level execution.steps.

Source types (docker, ecr, gcr, gar, acr, har, repository) match /create-sbom — see skills/create-sbom/references/sbom-orchestration-step.md for provider-specific source.spec fields.

Full UI mapping: references/sbom-enforcement-step.md.

Insert step into pipeline YAML
  • Insert at Phase 3 placement — after generate_sbom / SscaOrchestration when possible.
  • Do not modify unrelated steps, variables, or failure strategies.
  • Step identifier: enforce_sbom (rename if duplicate).
  • CI: same spec.execution.steps list as orchestration.
  • CD: inside the containerized step group only.
Update pipeline via MCP
harness_update
  resource_type: pipeline
  resource_id: <pipeline_identifier>
  org_id: <organization>
  project_id: <project>
  body: { yamlPipeline: "<updated pipeline YAML>" }

On validation errors, read the API message, fix fields (often verifyAttestation shape or policy.policySets), retry.

Provide summary

Report the results to the user (same pattern as /configure-repo-scan — do not execute the pipeline):

## SBOM Policy Enforcement Configured

**Pipeline:** <pipeline_name>
**Step:** SBOM Policy Enforcement (SscaEnforcement | CdSscaEnforcement)
**Location:** Stage "<stage_name>", <position>
**Source:** <type> — <connector/registry> — <image or repo>
**Verify attestation:** Keyless (Harness OIDC) — or as configured
**Policy sets:** <list>

**Pipeline URL:** https://app.harness.io/ng/account/<account_id>/module/ci/orgs/<org_id>/projects/<project_id>/pipelines/<pipeline_id>/pipeline-studio/

**Note:** Review the SBOM Policy Enforcement step in Pipeline Studio to adjust Advanced settings.

### Next Steps
1. Run the pipeline via `/run-pipeline` to verify enforcement executes successfully
2. If the run fails, diagnose with `/debug-pipeline`
3. View policy evaluation on the execution **Supply Chain** tab and Artifacts → **Policy Violations**
4. If **Failed** due to policy deny, tune policies via `/create-policy` (entity-sbom.md)
5. Add or adjust SBOM generation with `/create-sbom` if SBOM was missing
6. Automate with `/create-trigger`

CD pipelines: note in the summary if runtime inputs (service artifact, environment, infrastructure) will be required at run time — the user provides those via /run-pipeline or Harness UI Run.


Examples

Enforce after existing SBOM step
/enforce-sbom
Add SBOM policy enforcement to backend-api pipeline after Generate SBOM — keyless verify, policy set sbom_prod_rules
CD pipeline before deploy
/enforce-sbom
Enforce SBOM policies in deploy stage before K8s rolling deploy for myapp:v7
Defaults
/enforce-sbom
Use defaults — same image as SBOM orchestration step, Harness OIDC verify

Performance Notes

  • Only existing pipelines — do not offer to create new pipelines (you may append a Deploy stage to an existing pipeline).
  • Wizard UX is mandatory — one question per turn; see references/interactive-wizard-flow.md.
  • CI-only + CD enforcement: allowed — Phase 3b adds Deploy stage + containerized group; do not redirect to CI unless the user chooses CI placement.
  • Reuse SscaOrchestration source + image when present — avoids drift from generation step.
  • List policy_set via MCP before Phase 9 — do not invent policy set identifiers.
  • Enforcement after SBOM exists; orchestration and enforcement run sequentially.
  • CD: CdSscaEnforcement only in containerized step groups.
  • Do not execute pipelines in this skill — use /run-pipeline after configuration (same as /configure-repo-scan).
  • Pair with /create-sbom (generate) and /create-policy (OPA rules).

Troubleshooting

No SBOM / Orchestration Step in Pipeline
  • Add /create-sbom first, or ingest SBOM per Harness docs.
  • Enforcement evaluates components from an existing SBOM for the artifact.
No Policy Sets Found
  • harness_list(resource_type="policy_set") at project/org/account scope.
  • Create SBOM policies (package sbom) and a policy set with onstep via /create-policy.
Policy Evaluation Failed (Deny)
  • Review deny/allow lists in policy Rego (skills/create-policy/references/entity-sbom.md).
  • Check execution Supply Chain → policy violations for component UUIDs.
Attestation Verification Failed
  • Verification method must match SBOM Orchestration attestation (keyless vs key-based).
  • Keyless non-harness: configure OIDC connector for keyless signing (SCS → Manage → Configuration).
  • Key-based: public key file secret must match the key pair used when SBOM was attested.
Wrong Image / No SBOM for Artifact
  • Use the same source.spec.image as SscaOrchestration.
  • Symptom: policy passes but wrong artifact — image mismatch.
CD Step Validation Errors
  • CdSscaEnforcement requires spec.infrastructure and containerized execution.
  • Place inside stepGroup with stepGroupInfra — not top-level execution.steps on a Deployment stage.
  • See skills/create-sbom/references/cd-containerized-step-group.md.
User Chose CD on CI-Only Pipeline
  • Expected — run Phase 3b; do not re-ask Placement with only CI options unless the user changes direction.
  • SBOM must still exist (from CI SscaOrchestration or ingestion); enforcement in CD uses the same artifact image/expression.
Pipeline Update Validation Errors
  • DUPLICATE_IDENTIFIER — rename enforce_sbom.
  • Invalid policy.policySets — use policy set identifiers, not display names.
  • verifyAttestation shape — align with upstream attestation; see reference doc.
MCP Errors
  • CONNECTOR_NOT_FOUND — verify connector in Project Settings.
  • ACCESS_DENIED — PAT needs pipeline edit and policy read permissions.
Pipeline Run Failed
  • Use /run-pipeline to execute and /debug-pipeline to diagnose failures
  • Missing runtime inputs: provide branch/tag or deploy inputs via /run-pipeline or Harness UI Run
  • Policy deny fails the step — expected when components violate rules; report violations clearly

© harness, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in skills/enforce-sbom of harness/harness-skills.

  • SKILL.md
  • references/interactive-wizard-flow.md
  • references/sbom-enforcement-step.md

Open the folder on GitHubat commit c25faee

Compare with similar skills

Enforce Sbom next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Enforce Sbom compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Enforce Sbom this skillharness/harness-skills115—~3.9kAutomated safety check: PassApache-2.0
Performing Container Security Scanning With Trivymukul975/Anthropic-Cybersecurity-Skills34k—~818Automated safety check: PassApache-2.0
Triage Image Cvesactivepieces/activepieces25k—~3.6kAutomated safety check: PassCustom licence
Container Scanning with GrypeAgentSecOps/SecOpsAgentKit2201 repos~2.5kAutomated safety check: PassCustom licence
Container Securityhardw00t/ai-security-arsenal104—~2.8kAutomated safety check: PassNone
Sca TrivyAgentSecOps/SecOpsAgentKit2202 repos~3.7kAutomated safety check: PassCustom licence

Similar skills

  • Performing Container Security Scanning With Trivy

    mukul975/Anthropic-Cybersecurity-Skills

    Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed…

    34k GitHub stars~818 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Triage Image Cves

    activepieces/activepieces

    Scan an Activepieces Docker image with grype for OS/base-image (deb) and application (npm) CVEs of High/Critical severity.

    25k GitHub stars~3.6k tokensUpdated today
    SecurityAuto-check passed
  • Container Scanning with Grype

    AgentSecOps/SecOpsAgentKit

    Scans container images, filesystems and SBOMs with Grype for known vulnerabilities, ranks them by CVSS, EPSS and CISA KEV, and wires scans into CI/CD thresholds.

    220 GitHub starsUsed in 1 repo~2.5k tokens
    SecurityAuto-check passed
  • Container Security

    hardw00t/ai-security-arsenal

    Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and…

    104 GitHub stars~2.8k tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • Sca Trivy

    AgentSecOps/SecOpsAgentKit

    Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…

    220 GitHub starsUsed in 2 repos~3.7k tokens
    SecurityAuto-check passed
  • Container Security Hardening

    sickn33/agentic-awesome-skills

    Harden Docker/container images and runtime deployments with secure base images, non-root users, CVE scanning, SBOM/signing, seccomp/AppArmor, and Kubernetes pod security controls.

    47k GitHub starsUsed in 1 repo~1k tokens
    SecurityAuto-check: notes

More from harness/harness-skills

All 24 skills in this repo
  • Audit Report

    harness/harness-skills

    Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.

    115 GitHub stars~1.3k tokensUpdated 2 days ago
    Auto-check passed
  • Chaos Dr Test

    harness/harness-skills

    A skill your agent uses when working with Chaos Engineering steps inside a Harness pipeline.

    115 GitHub stars~2.6k tokensUpdated 2 days ago
    Auto-check passed
  • Chaos Experiment

    harness/harness-skills

    A skill your agent uses when the user asks to create, edit, update, design, or configure a Harness Chaos Experiment — including faults, probes, actions, experiment YAML, fault injection, pod-delete…

    115 GitHub stars~1.6k tokensUpdated 2 days ago
    Auto-check passed
  • Cleanup Feature Flags

    harness/harness-skills

    Remove a launched Harness FME feature flag from application code, keeping the treatment FME serves today, and open a pull request.

    115 GitHub stars~2.4k tokensUpdated 2 days ago
    Auto-check passed
  • Configure Repo Scan

    harness/harness-skills

    Configure code scanning in Harness pipelines using STO security scanners.

    115 GitHub stars~2.2k tokensUpdated 2 days ago
    Auto-check passed
  • Create Agent Template

    harness/harness-skills

    Generate Harness Agent Template files for AI-powered automation agents.

    115 GitHub stars~2.2k tokensUpdated 2 days ago
    Auto-check passed

Works with

Categories

Questions about Enforce Sbom

What does Enforce Sbom do?

Add an SBOM Policy Enforcement (SscaEnforcement / CdSscaEnforcement) step to an existing Harness pipeline to verify SBOM attestations and apply OPA SBOM policy sets. Enforce Sbom is an agent skill from harness/harness-skills. Add an SBOM Policy Enforcement (SscaEnforcement / CdSscaEnforcement) step to an existing Harness pipeline to verify SBOM attestations and apply OPA SBOM policy sets.

When should I use Enforce Sbom?

Enforce Sbom fits situations like: asked to enforce SBOM policies; add SBOM policy enforcement; verify SBOM attestation in pipeline; block non-compliant components.

How do I install Enforce Sbom in Claude Code?

Run `npx skills add harness/harness-skills --skill enforce-sbom -a claude-code`. Or copy the skill folder (skills/enforce-sbom in harness/harness-skills) into .claude/skills/enforce-sbom in your project. Claude Code loads it when a task matches its description.

How do I install Enforce Sbom in Codex?

Run `npx skills add harness/harness-skills --skill enforce-sbom -a codex`. Or copy the skill folder (skills/enforce-sbom in harness/harness-skills) into .agents/skills/enforce-sbom in your project. Codex loads it when a task matches its description.

Can I use Enforce Sbom in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add harness/harness-skills --skill enforce-sbom -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/enforce-sbom, .gemini/skills/enforce-sbom, .github/skills/enforce-sbom and .opencode/skills/enforce-sbom in your project.

What does Enforce Sbom need to run?

SKILL.md names no scripts, command-line tools or credentials: Enforce Sbom is instructions for the agent only. Our summary lists: Docker. Compatibility (from SKILL.md): Requires Harness MCP v2 server (harness-mcp-v2).

Does Enforce Sbom access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Enforce Sbom safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Enforce Sbom use?

Enforce Sbom is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Enforce Sbom use?

About 3.9k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.3k tokens, read only when the agent opens those files.

What are the alternatives to Enforce Sbom?

Skills that share tags, products or a category with Enforce Sbom: Performing Container Security Scanning With Trivy (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Triage Image Cves (activepieces/activepieces, 25k stars), Container Scanning with Grype (AgentSecOps/SecOpsAgentKit, 220 stars) and Container Security (hardw00t/ai-security-arsenal, 104 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Enforce Sbom?

harness (a GitHub organization) maintains it in harness/harness-skills, which has 115 GitHub stars. The repository holds 24 skills in this directory. The repository was last updated on October 6, 2026.

Source: harness/harness-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.