Warp Vulnerability Triage
warpdotdev/warp
Gathers security findings from Dependabot, GCP container scanning, Docker Scout and Linear security issues, then triages and remediates them across Warp's repos and images.
Add a SLSA Generation step (YAML type: provenance) to an existing Harness pipeline to generate SLSA provenance and optionally attest with Cosign (keyless, key-based, or Vault).
$ npx skills add harness/harness-skills --skill generate-slsa -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install harness/harness-skills generate-slsa --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/harness/harness-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/generate-slsa .claude/skills/generate-slsa && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "generate-slsa" agent skill from https://github.com/harness/harness-skills/tree/main/skills/generate-slsa into .claude/skills/generate-slsa/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "generate-slsa", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/harness/harness-skills/tree/main/skills/generate-slsaType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add harness/harness-skills --skill generate-slsa -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install harness/harness-skills generate-slsa --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/harness/harness-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/generate-slsa .agents/skills/generate-slsa && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "generate-slsa" agent skill from https://github.com/harness/harness-skills/tree/main/skills/generate-slsa into .agents/skills/generate-slsa/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "generate-slsa", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add harness/harness-skills --skill generate-slsa -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install harness/harness-skills generate-slsa --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/harness/harness-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/generate-slsa .cursor/skills/generate-slsa && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "generate-slsa" agent skill from https://github.com/harness/harness-skills/tree/main/skills/generate-slsa into .cursor/skills/generate-slsa/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "generate-slsa", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/harness/harness-skills.git --path skills/generate-slsa--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add harness/harness-skills --skill generate-slsa -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install harness/harness-skills generate-slsa --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/harness/harness-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/generate-slsa .gemini/skills/generate-slsa && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "generate-slsa" agent skill from https://github.com/harness/harness-skills/tree/main/skills/generate-slsa into .gemini/skills/generate-slsa/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "generate-slsa", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install harness/harness-skills generate-slsaInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add harness/harness-skills --skill generate-slsa -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/harness/harness-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/generate-slsa .github/skills/generate-slsa && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "generate-slsa" agent skill from https://github.com/harness/harness-skills/tree/main/skills/generate-slsa into .github/skills/generate-slsa/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "generate-slsa", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add harness/harness-skills --skill generate-slsa -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install harness/harness-skills generate-slsa --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/harness/harness-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/generate-slsa .opencode/skills/generate-slsa && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "generate-slsa" agent skill from https://github.com/harness/harness-skills/tree/main/skills/generate-slsa into .opencode/skills/generate-slsa/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "generate-slsa", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
generate-slsaAdd a SLSA Generation step (YAML type: provenance) to an existing Harness pipeline to generate SLSA provenance and optionally attest with Cosign (keyless, key-based, or Vault).
Generate Slsa is an agent skill from harness/harness-skills. Add a SLSA Generation step (YAML type: provenance) to an existing Harness pipeline to generate SLSA provenance and optionally attest with Cosign (keyless, key-based, or Vault). Supports container images (Docker, ECR, GCR, GAR, ACR, HAR) and Harness Local Stage artifacts. Place after image build/push; run sequentially after SBOM steps, not in parallel. Only works with existing pipelines. Use when asked to generate SLSA, add SLSA provenance, SLSA Generation step, attest SLSA, or configure SLSA Level 3 provenance in…
Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/cd-containerized-step-group.md`, `references/interactive-wizard-flow.md` and `references/slsa-generation-step.md`). Compatibility notes: Requires Harness MCP v2 server (harness-mcp-v2)
It sits in Security, covering Supply chain security and Containers. It works with Docker. The repository describes itself as: A collection of structured AI agent skills that enable Claude Code, Cursor, GitHub Copilot, and other AI coding assistants to create, operate, debug, and govern Harness CI/CD… The licence is Apache-2.0.
12 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit c25faee. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are yaml).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Requires Harness MCP v2 server (harness-mcp-v2)
From compatibility in the SKILL.md frontmatter.
Generate Slsa loads about 3k tokens when it runs, and up to ~6.5k if it reads all its reference files. Until then it costs about 178 tokens; SKILL.md has 1,009 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from harness/harness-skills at commit c25faee, republished under its Apache-2.0 licence (© harness). 1,009 words, ~2,962 tokens.
.claude/skills/generate-slsa/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Add a SLSA Generation step to an existing Harness pipeline to generate SLSA provenance and
optionally attest/sign the .att file in the container registry. Pipeline YAML uses
type: provenance (UI label: SLSA Generation; do not use SlsaGeneration — API rejects it).
This skill only works with existing pipelines — do not create standalone SLSA-only pipelines.
Prerequisites: Image must be built and pushed (or available in registry) before SLSA runs.
Key-based attestation requires Cosign key pair secrets (/create-secret). Harness Cloud builds
enable SLSA Level 3 provenance when using hosted infrastructure.
Guide the user through a step-by-step interactive wizard (same UX as /configure-repo-scan):
references/interactive-wizard-flow.mdreferences/slsa-generation-step.mdreferences/cd-containerized-step-group.mdAskQuestion when available; otherwise numbered options with (Recommended).Pipeline · Placement · Source · Details · Attestation · Submitharness_get before placement/source questions.provenance / SscaOrchestration steps (UI: SLSA Generation).harness_update only after user confirms.harness_update, provide a configuration summary and
point the user to /run-pipeline to execute. Do not call harness_execute, poll
executions, or run harness_diagnose in this skill (same pattern as /configure-repo-scan).SscaOrchestration exists, place SLSA after it; never parallel (Cosign race).stepGroup only — see CD reference.Full phase prompts: references/interactive-wizard-flow.md.
| Phase | Breadcrumb | Action |
|---|---|---|
| 0 | Pipeline | AskQuestion: pipeline URL ready? |
| 1 | Pipeline | Collect URL → harness_get |
| 2 | Pipeline | Display structure; note build/push + SBOM steps |
| 3 | Placement | Mandatory AskQuestion: stage + position (after build/push recommended) |
| 3b | Placement (CD) | Service, env, infra, step group if new Deploy stage |
| 4 | Source | AskQuestion: Third-Party, HAR, or Local |
| 5 | Source | AskQuestion: registry provider (Third-Party only) |
| 6 | Details | Connector (skip if obvious) |
| 7 | Details | Image/repo; optional digest expression |
| 8 | Attestation | AskQuestion: keyless, keybased, vault, or none |
| 9 | Submit | AskQuestion: confirm pipeline update |
After Phase 9 confirm → generate YAML, insert step, harness_update, then provide summary (do not run the pipeline).
| Stage type | Placement notes |
|---|---|
CI | Recommended — immediately after BuildAndPush* or image push Run step |
Deployment | Containerized step group only; before deploy — uncommon for generation |
Security | End of stage when scanning pre-built registry images |
From BuildAndPushDockerRegistry, BuildAndPushECR, Run, Plugin, SscaOrchestration,
provenance (SLSA Generation), or SscaArtifactSigning steps — reuse connectorRef / connector.
Use only wizard answers. Default attestation: keyless Harness OIDC when user chose defaults.
Docker Registry — matches reference UI (key-based attestation):
- step:
identifier: slsageneration
name: slsa-generation
type: provenance
spec:
source:
type: docker
spec:
connector: lavakush07
repo: lavakush07/easy-buggy-app:blog
attestation:
type: keybased
spec:
privateKey: account.cosign_private_key
password: account.cosign_password
timeout: 15mKeyless attestation (default for “use defaults”):
attestation:
type: keyless
spec:
oidcProvider: harnessWith digest from Build and Push:
source:
type: docker
spec:
connector: <docker_registry_connector>
repo: <org>/<repo>:<tag>
digest: <+pipeline.stages.<stage>.spec.execution.steps.<build_step>.output.outputVariables.digest>Amazon ECR:
source:
type: ecr
spec:
connector: <registry_connector>
image: <repo/name>
region: <aws_region>
account: <aws_account_id>Google GCR / GAR / Azure ACR / HAR / Local: see references/slsa-generation-step.md.
No attestation: omit attestation block.
generate_sbom when both exist).slsageneration (suffix _cd in CD when CI already has one).stepGroup.steps only.harness_update
resource_type: pipeline
resource_id: <pipeline_identifier>
org_id: <organization>
project_id: <project>
body: { yamlPipeline: "<updated pipeline YAML>" }On validation errors, read the API message, fix fields (often repo vs image, attestation spec), retry.
Report the results to the user (same pattern as /configure-repo-scan — do not execute the pipeline):
## SLSA Generation Configured
**Pipeline:** <pipeline_name>
**Step:** SLSA Generation (`provenance`)
**Location:** Stage "<stage_name>", <position>
**Source:** docker — <connector> — <repo/image>
**Attestation:** Key-based (account.cosign_private_key) — or as configured
**Pipeline URL:** https://app.harness.io/ng/account/<account_id>/module/ci/orgs/<org_id>/projects/<project_id>/pipelines/<pipeline_id>/pipeline-studio/
**Note:** Review the SLSA Generation step in Pipeline Studio to adjust Advanced settings.
**Provenance:** After a successful run, view on the Supply Chain tab and in SCS Artifacts.
### Next Steps
1. Run the pipeline via `/run-pipeline` to verify the SLSA Generation step executes successfully
2. If the run fails, diagnose with `/debug-pipeline`
3. Add SLSA verification with `/enforce-slsa`
4. Pair with `SscaOrchestration` (Generate SBOM) — run SBOM then SLSA sequentially
5. Automate with `/create-trigger`CD pipelines: note in the summary if runtime inputs (service artifact, environment, infrastructure)
will be required at run time — the user provides those via /run-pipeline or Harness UI Run.
/generate-slsa
Add SLSA Generation to my CI pipeline after docker push — lavakush07/easy-buggy-app:blog, key-based attest with account cosign secrets/generate-slsa
Use defaults — keyless Harness OIDC after Build_and_Push step/generate-slsa
Generate SLSA for image from Build_and_Push digest output — keyless attest/generate-slsa
add slsa to the pipelineAgent must still run Phase 2 + Phase 3 — do not assume stage or skip placement.
references/interactive-wizard-flow.md.type is provenance — not SlsaGeneration (API enum rejects SlsaGeneration).source.spec.repo (not image; SBOM SscaOrchestration uses image for docker)./create-secret)./enforce-slsa; see CD reference./run-pipeline after configuration (same as /configure-repo-scan)./manage-supply-chain instead.harness_list (resource_type: pipeline).connectorRef; harness_search for Docker registry connectors.repo string — e.g. lavakush07/easy-buggy-app:blog.ecdsa-p256..att upload..att in registry — steps ran in parallel.provenance (SLSA Generation) in Deploy stages must be inside stepGroup with stepGroupInfra.references/cd-containerized-step-group.md.SlsaGeneration Step Typedoes not have a value in the enumeration for SlsaGeneration.type: provenance — validate with harness_schema(resource_type="pipeline", path="steps")./run-pipeline to execute and /debug-pipeline to diagnose failures/run-pipeline or Harness UI Run — do not guess runtime inputsCONNECTOR_NOT_FOUND — verify connector identifier.ACCESS_DENIED — PAT needs pipeline edit permission.© harness, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (references) in skills/generate-slsa of harness/harness-skills.
Open the folder on GitHubat commit c25faee
Generate Slsa next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Generate Slsa this skillharness/harness-skills | 115 | — | ~3k | Automated safety check: Pass | Apache-2.0 | |
| Warp Vulnerability Triagewarpdotdev/warp | 65k | 1 repos | ~2.1k | Automated safety check: Pass | AGPL-3.0 | |
| Container Scanning with GrypeAgentSecOps/SecOpsAgentKit | 220 | 1 repos | ~2.5k | Automated safety check: Pass | Custom licence | |
| Container Securityhardw00t/ai-security-arsenal | 104 | — | ~2.8k | Automated safety check: Pass | None | |
| Sca TrivyAgentSecOps/SecOpsAgentKit | 220 | 2 repos | ~3.7k | Automated safety check: Pass | Custom licence | |
| Container Security Hardeningsickn33/agentic-awesome-skills | 47k | 1 repos | ~1k | Automated safety check: Notes | MIT |
warpdotdev/warp
Gathers security findings from Dependabot, GCP container scanning, Docker Scout and Linear security issues, then triages and remediates them across Warp's repos and images.
AgentSecOps/SecOpsAgentKit
Scans container images, filesystems and SBOMs with Grype for known vulnerabilities, ranks them by CVSS, EPSS and CISA KEV, and wires scans into CI/CD thresholds.
hardw00t/ai-security-arsenal
Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and…
AgentSecOps/SecOpsAgentKit
Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…
sickn33/agentic-awesome-skills
Harden Docker/container images and runtime deployments with secure base images, non-root users, CVE scanning, SBOM/signing, seccomp/AppArmor, and Kubernetes pod security controls.
cdxgen/cdxgen
Generates CycloneDX BOMs for container images, OCI archives, mounted root filesystems, Electron ASAR archives, caxa executables, binaries, and Kubernetes or Dockerfile manifests using OWASP cdxgen…
harness/harness-skills
Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.
harness/harness-skills
A skill your agent uses when working with Chaos Engineering steps inside a Harness pipeline.
harness/harness-skills
A skill your agent uses when the user asks to create, edit, update, design, or configure a Harness Chaos Experiment — including faults, probes, actions, experiment YAML, fault injection, pod-delete…
harness/harness-skills
Remove a launched Harness FME feature flag from application code, keeping the treatment FME serves today, and open a pull request.
harness/harness-skills
Configure code scanning in Harness pipelines using STO security scanners.
harness/harness-skills
Generate Harness Agent Template files for AI-powered automation agents.
Works with
Categories
Add a SLSA Generation step (YAML type: provenance) to an existing Harness pipeline to generate SLSA provenance and optionally attest with Cosign (keyless, key-based, or Vault). Generate Slsa is an agent skill from harness/harness-skills. Add a SLSA Generation step (YAML type: provenance) to an existing Harness pipeline to generate SLSA provenance and optionally attest with Cosign (keyless, key-based, or Vault).
Generate Slsa fits situations like: asked to generate SLSA; add SLSA provenance; SLSA Generation step; configure SLSA Level 3 provenance in a pipeline.
Run `npx skills add harness/harness-skills --skill generate-slsa -a claude-code`. Or copy the skill folder (skills/generate-slsa in harness/harness-skills) into .claude/skills/generate-slsa in your project. Claude Code loads it when a task matches its description.
Run `npx skills add harness/harness-skills --skill generate-slsa -a codex`. Or copy the skill folder (skills/generate-slsa in harness/harness-skills) into .agents/skills/generate-slsa in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add harness/harness-skills --skill generate-slsa -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/generate-slsa, .gemini/skills/generate-slsa, .github/skills/generate-slsa and .opencode/skills/generate-slsa in your project.
SKILL.md names no scripts, command-line tools or credentials: Generate Slsa is instructions for the agent only. Our summary lists: Docker. Compatibility (from SKILL.md): Requires Harness MCP v2 server (harness-mcp-v2).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Generate Slsa is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.6k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Generate Slsa: Warp Vulnerability Triage (warpdotdev/warp, 65k stars), Container Scanning with Grype (AgentSecOps/SecOpsAgentKit, 220 stars), Container Security (hardw00t/ai-security-arsenal, 104 stars) and Sca Trivy (AgentSecOps/SecOpsAgentKit, 220 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
harness (a GitHub organization) maintains it in harness/harness-skills, which has 115 GitHub stars. The repository holds 24 skills in this directory. The repository was last updated on October 6, 2026.
Source: harness/harness-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.