Iron Proxy Gateway for NanoClaw
nanocoai/nanoclaw
Installs or refreshes Iron Proxy and its Iron Control web console for NanoClaw, with a local Docker setup, database, credentials and a human approval bridge.
Add an Artifact Signing (SscaArtifactSigning) step to an existing Harness pipeline to Cosign-sign container or local-stage artifacts with keyless, key-based, or Vault signing.
$ npx skills add harness/harness-skills --skill sign-artifact -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install harness/harness-skills sign-artifact --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/harness/harness-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/sign-artifact .claude/skills/sign-artifact && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "sign-artifact" agent skill from https://github.com/harness/harness-skills/tree/main/skills/sign-artifact into .claude/skills/sign-artifact/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sign-artifact", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/harness/harness-skills/tree/main/skills/sign-artifactType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add harness/harness-skills --skill sign-artifact -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install harness/harness-skills sign-artifact --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/harness/harness-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/sign-artifact .agents/skills/sign-artifact && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "sign-artifact" agent skill from https://github.com/harness/harness-skills/tree/main/skills/sign-artifact into .agents/skills/sign-artifact/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sign-artifact", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add harness/harness-skills --skill sign-artifact -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install harness/harness-skills sign-artifact --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/harness/harness-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/sign-artifact .cursor/skills/sign-artifact && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "sign-artifact" agent skill from https://github.com/harness/harness-skills/tree/main/skills/sign-artifact into .cursor/skills/sign-artifact/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sign-artifact", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/harness/harness-skills.git --path skills/sign-artifact--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add harness/harness-skills --skill sign-artifact -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install harness/harness-skills sign-artifact --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/harness/harness-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/sign-artifact .gemini/skills/sign-artifact && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "sign-artifact" agent skill from https://github.com/harness/harness-skills/tree/main/skills/sign-artifact into .gemini/skills/sign-artifact/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sign-artifact", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install harness/harness-skills sign-artifactInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add harness/harness-skills --skill sign-artifact -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/harness/harness-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/sign-artifact .github/skills/sign-artifact && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "sign-artifact" agent skill from https://github.com/harness/harness-skills/tree/main/skills/sign-artifact into .github/skills/sign-artifact/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sign-artifact", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add harness/harness-skills --skill sign-artifact -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install harness/harness-skills sign-artifact --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/harness/harness-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/sign-artifact .opencode/skills/sign-artifact && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "sign-artifact" agent skill from https://github.com/harness/harness-skills/tree/main/skills/sign-artifact into .opencode/skills/sign-artifact/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sign-artifact", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
sign-artifactAdd an Artifact Signing (SscaArtifactSigning) step to an existing Harness pipeline to Cosign-sign container or local-stage artifacts with keyless, key-based, or Vault signing.
Sign Artifact is an agent skill from harness/harness-skills. Add an Artifact Signing (SscaArtifactSigning) step to an existing Harness pipeline to Cosign-sign container or local-stage artifacts with keyless, key-based, or Vault signing. Supports Third-Party registries (Docker, ECR, GCR, GAR, ACR), Harness Artifact Registry (HAR), and Harness Local Stage artifacts. Place after image build/push; optionally upload .sig to the registry. Only works with existing pipelines. Use when asked to sign artifacts, add artifact signing, Cosign sign image, attach signature to registry…
Its SKILL.md is about 4.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/artifact-signing-step.md`, `references/cd-containerized-step-group.md` and `references/interactive-wizard-flow.md`). Compatibility notes: Requires Harness MCP v2 server (harness-mcp-v2)
It sits in DevOps & Cloud, covering Containers. It works with Docker. The repository describes itself as: A collection of structured AI agent skills that enable Claude Code, Cursor, GitHub Copilot, and other AI coding assistants to create, operate, debug, and govern Harness CI/CD… The licence is Apache-2.0.
12 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit c25faee. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are yaml).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Requires Harness MCP v2 server (harness-mcp-v2)
From compatibility in the SKILL.md frontmatter.
Sign Artifact loads about 4.6k tokens when it runs, and up to ~9.5k if it reads all its reference files. Until then it costs about 183 tokens; SKILL.md has 1,813 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from harness/harness-skills at commit c25faee, republished under its Apache-2.0 licence (© harness). 1,813 words, ~4,611 tokens.
.claude/skills/sign-artifact/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Add an Artifact Signing (SscaArtifactSigning) step to an existing Harness pipeline. The step
retrieves an artifact from a registry or local workspace, signs it with Cosign, and optionally pushes
the .sig signature file back to the registry.
This skill only works with existing pipelines — do not create standalone signing-only pipelines.
Prerequisites: Container images must be built and pushed (or available in registry) before signing.
Key-based signing requires Cosign key pair file secrets (/create-secret). Harness docs note that
Deploy-stage signing is not yet supported — prefer CI or Security stages.
Guide the user through a step-by-step interactive wizard (same UX as /verify-sign):
references/interactive-wizard-flow.mdreferences/artifact-signing-step.mdreferences/cd-containerized-step-group.mdAskQuestion when available; otherwise numbered options with (Recommended).Pipeline · Placement · Source · Details · Signing · Upload · Submitharness_get before placement/source questions.SscaArtifactSigning steps.harness_update only after user confirms.harness_update, provide a configuration summary and
point the user to /run-pipeline to execute. Do not call harness_execute, poll
executions, or run harness_diagnose in this skill (same pattern as /configure-repo-scan).SscaOrchestration or provenance exists, place signing after those steps sequentially (Cosign registry race).SscaArtifactSigning already exists, ask: update in place, add a second step, or abort. If existing step has uploadSignature.upload: false (or block missing) and user wants .sig in registry, set upload: true..sig defaults OFF in Harness — UI checkbox Attach signature to Artifact Registry is unchecked by default. For container images, always set uploadSignature.upload: true unless the user explicitly opts out. Confirm this in Phase 9 and in the submit summary..sig after run — when upload is enabled, after the user runs via /run-pipeline,
check step logs for signature push success; see Troubleshooting if registry shows no signature tag.harness_list with
filters: { type: "<ConnectorType>" } and size: 100 at project, org, and account scope; merge
and present every match in AskQuestion. See references/interactive-wizard-flow.md Phase 6.failureStrategies on update — when inserting signing into a CI stage, ensure the stage
has failureStrategies with MarkAsFailure (not Ignore). Missing or Ignore hides signing
failures as IgnoreFailed while the pipeline continues.harness_update must start from the exact yamlPipeline returned by
harness_get in this session. Insert or update only the SscaArtifactSigning step (and CI
failureStrategies if required). Never add, remove, or reorder other steps. Never add
HarnessSAST, HarnessSCA, STO scanners, or /configure-repo-scan steps — use those skills only
when the user explicitly asks for code/container scanning.Full phase prompts: references/interactive-wizard-flow.md.
| Phase | Breadcrumb | Action |
|---|---|---|
| 0 | Pipeline | AskQuestion: pipeline URL ready? |
| 1 | Pipeline | Collect URL → harness_get |
| 2 | Pipeline | Display structure; note build/push + existing signing steps; flag missing uploadSignature.upload: true |
| 2b | Pipeline | If SscaArtifactSigning exists — AskQuestion: update, add second, or abort |
| 3 | Placement | Mandatory AskQuestion: stage + position + anchor push step (after build/push recommended) |
| 4 | Source | AskQuestion: Third-Party, HAR, or Local |
| 5 | Source | AskQuestion: registry provider (Third-Party only) |
| 6 | Details | Connector — list all matches via harness_list + filters.type (skip if obvious) |
| 7 | Details | Image / registry fields; optional digest expression |
| 8 | Signing | AskQuestion: keyless, keybased, vault |
| 9 | Upload | AskQuestion: attach .sig to registry (container images only) |
| 10 | Submit | AskQuestion: confirm pipeline update |
After Phase 10 confirm → generate YAML, insert step, harness_update, then provide summary (do not run the pipeline).
| Stage type | Placement notes |
|---|---|
CI | Recommended — immediately after BuildAndPush* or image push step |
Security | End of stage when signing pre-built registry images |
Deployment | Not supported by Harness today — warn user; prefer CI signing |
From BuildAndPushDockerRegistry, BuildAndPushECR, BuildAndPushGCR, BuildAndPushGAR,
BuildAndPushACR, Kaniko/Run push steps, SscaOrchestration, SscaArtifactSigning, or
provenance steps — reuse connectorRef / connector. Signing source uses connector (not
connectorRef).
Use only wizard answers. Docker Third-Party uses source.spec.image (not repo).
Docker Registry — key-based signing (Harness docs reference):
- step:
identifier: artifactsigning
name: Artifact Signing
type: SscaArtifactSigning
spec:
source:
type: docker
spec:
connector: lavakush07
image: lavakush07/easy-buggy-app:v5
signing:
type: cosign
spec:
private_key: account.cosign_private_key
password: account.cosign_password
uploadSignature:
upload: true
timeout: 15mKeyless signing (Harness OIDC) — include upload when pushing .sig:
signing:
type: keyless
spec:
oidcProvider: harness
uploadSignature:
upload: trueNon-Harness keyless OIDC (requires account Connector for Keyless Signing):
signing:
type: keyless
spec:
oidcProvider: non-harness
uploadSignature:
upload: trueHarness Artifact Registry (HAR):
source:
type: har
spec:
registry: <har_registry_identifier>
image: my-image:v5Harness Local Stage (non-container):
source:
type: local
spec:
workspace: <path_in_workspace>
artifact_name: my-artifact.jar
version: "1.0.0"No registry upload: omit uploadSignature or set upload: false. Harness still stores signature
metadata internally — but external tools and registry-side verify need upload: true.
Amazon ECR / GCR / GAR / ACR: see references/artifact-signing-step.md — always include
uploadSignature.upload: true when user expects .sig in the registry.
Critical: Parse yamlPipeline from harness_get and treat it as the only source of truth. Do not
rebuild the pipeline from examples, templates, or assumptions (e.g. cloneCodebase: true does not
imply a Harness Code Scan step).
failureStrategies if the stage has none or uses Ignore (use MarkAsFailure).harness_update, diff mentally: step count must increase by at most one (or zero if
updating an existing SscaArtifactSigning). If any new step types appear (e.g. HarnessSAST),
stop and fix the YAML — do not save.artifactsigning (use artifactsigning_2, etc. if duplicate). CD Deploy placement
is unsupported — do not use _cd suffix for signing steps.CI stage must include failureStrategies (API may accept saves without it, but runs show
IgnoreFailed when signing fails):
failureStrategies:
- onFailure:
errors: [AllErrors]
action:
type: MarkAsFailureharness_update
resource_type: pipeline
resource_id: <pipeline_identifier>
org_id: <organization>
project_id: <project>
body: { yamlPipeline: "<updated pipeline YAML>" }On validation errors, read the API message. Common fixes: image vs repo, signing vs attestation,
private_key / password secret refs for key-based cosign.
Report the results to the user (same pattern as /configure-repo-scan — do not execute the pipeline):
## Artifact Signing Configured
**Pipeline:** <pipeline_name>
**Step:** Artifact Signing (SscaArtifactSigning)
**Location:** Stage "<stage_name>", <position>
**Source:** docker — <connector> — <image>
**Signing:** Keyless (Harness OIDC) — or as configured
**Upload .sig:** Yes / No
**Pipeline URL:** https://app.harness.io/ng/account/<account_id>/module/ci/orgs/<org_id>/projects/<project_id>/pipelines/<pipeline_id>/pipeline-studio/
**Note:** Review the Artifact Signing step in Pipeline Studio to adjust Advanced settings.
**Signature:** After a successful run, view on the Supply Chain tab and Chain of Custody.
### Next Steps
1. Run the pipeline via `/run-pipeline` to verify the Artifact Signing step executes successfully
2. If the run fails, diagnose with `/debug-pipeline`
3. If **no `.sig` in registry**, confirm `uploadSignature.upload: true` — see Troubleshooting
4. Add verification with `/verify-sign`
5. Add SBOM/SLSA **before** signing if not present (`/manage-supply-chain` or `SscaOrchestration` / `provenance`)
6. Automate with `/create-trigger`/sign-artifact
Add artifact signing after docker push — lavakush07/easy-buggy-app:v5, key-based with account cosign secrets, upload signature/sign-artifact
Use defaults — keyless Harness OIDC after Build_and_Push, attach signature to registry/sign-artifact
Sign image my-service:v2 from Harness Artifact Registry registry-id prod-har — keyless/sign-artifact
add signing to the pipelineAgent must still run Phase 2 + Phase 3 — do not assume stage or skip placement.
.sig in registry/sign-artifact
Signing step succeeded but no .sig in Docker Hub — update existing artifactsigning step to upload signatureAgent must inspect existing YAML for uploadSignature, set upload: true, ensure signing runs
after build/push sequentially, then run the pipeline via /run-pipeline.
references/interactive-wizard-flow.md.image — not repo (SLSA provenance uses repo; SBOM uses image).signing — not attestation (SLSA generation) or verifySign (verification).source.type: har with registry + image; offer even if UI shows only Third-Party + Local tiles.uploadSignature.upload: true. Harness UI defaults
this to unchecked — missing block = no registry upload./create-secret)./run-pipeline after configuration (same as /configure-repo-scan)./manage-supply-chain instead.harness_list (resource_type: pipeline).connectorRef.harness_list + filters: { type: "DockerRegistry" } (not harness_search, not
params.filterType). Query project, org, and account scopes; see Phase 6 in
references/interactive-wizard-flow.md.image string — e.g. lavakush07/easy-buggy-app:v5.registry identifier + image name with tag or digest.ecdsa-p256.signing.type: cosign with private_key + password if keybased fails validation..sig Not in Registry (step succeeded)Most common cause: uploadSignature.upload is missing or false. Harness defaults the UI checkbox
Attach signature to Artifact Registry to unchecked — signature is stored in Harness only.
Fix checklist:
uploadSignature.upload: true on the SscaArtifactSigning step (container images only).sha256-<digest>.sig) or OCI referrers — not always visible as a .sig file in the UI. Use
cosign verify CLI or Harness Supply Chain tab to confirm..sig or attestation in registry — steps ran in parallel.uploadSignature is absent, Harness treated upload as disabled.upload: true vs add new step.type must be SscaArtifactSigning.connector + image (not repo).uploadSignature.upload is boolean — UI checkbox "Attach signature to Artifact Registry"./run-pipeline to execute and /debug-pipeline to diagnose failuresinputs via /run-pipeline for codebase pipelinesIgnoreFailed, signing likely failed — inspect artifactsigning step logs;
add or fix failureStrategies: MarkAsFailure on the CI stageIgnoreFailed)failureStrategies or uses Ignore / non-blocking failure strategy.failureStrategies → MarkAsFailure on the CI stage, then re-run.yamlPipeline instead of the fetched YAML + signing insert.harness_get the pipeline, delete the unwanted HarnessSAST / STO step from YAML, save via
harness_update, or remove the step in Pipeline Studio.CONNECTOR_NOT_FOUND — verify connector identifier.ACCESS_DENIED — PAT needs pipeline edit permission.harness_update timeout — retry once; if MCP bubble times out, provide YAML summary for manual
paste in Pipeline Studio.© harness, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (references) in skills/sign-artifact of harness/harness-skills.
Open the folder on GitHubat commit c25faee
Sign Artifact next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Sign Artifact this skillharness/harness-skills | 115 | — | ~4.6k | Automated safety check: Pass | Apache-2.0 | |
| Iron Proxy Gateway for NanoClawnanocoai/nanoclaw | 31k | — | ~4.6k | Automated safety check: Notes | MIT | |
| GreptimeDB Dev Docker ImageGreptimeTeam/greptimedb | 6.7k | — | ~4k | Automated safety check: Notes | Apache-2.0 | |
| Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit | 260 | 6 repos | ~1.1k | Automated safety check: Notes | Custom licence | |
| LangBot Deployment Guidelangbot-app/LangBot | 18k | — | ~1.2k | Automated safety check: Notes | Apache-2.0 | |
| Build Openshell Mxc WindowsNVIDIA/OpenShell | 16k | — | ~4.9k | Automated safety check: Pass | Apache-2.0 |
nanocoai/nanoclaw
Installs or refreshes Iron Proxy and its Iron Control web console for NanoClaw, with a local Docker setup, database, credentials and a human approval bridge.
GreptimeTeam/greptimedb
Packages a locally built GreptimeDB debug binary into a development-only Docker image for local-cluster testing, with an optional push to a dev registry.
maslennikov-ig/claude-code-orchestrator-kit
Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…
langbot-app/LangBot
Deploys and configures a LangBot instance with Docker Compose or Kubernetes, covering config.yaml, the Box sandbox runtime, the plugin runtime and the global API key.
NVIDIA/OpenShell
Maintain and validate OpenShell's build-only Windows MSVC lane for x64 and ARM64.
NVIDIA/Megatron-LM
Moves Megatron-LM CI to a newer NVIDIA PyTorch base image, updating both the GitHub and GitLab pins together and handling the CI follow-up.
harness/harness-skills
Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.
harness/harness-skills
A skill your agent uses when working with Chaos Engineering steps inside a Harness pipeline.
harness/harness-skills
A skill your agent uses when the user asks to create, edit, update, design, or configure a Harness Chaos Experiment — including faults, probes, actions, experiment YAML, fault injection, pod-delete…
harness/harness-skills
Remove a launched Harness FME feature flag from application code, keeping the treatment FME serves today, and open a pull request.
harness/harness-skills
Configure code scanning in Harness pipelines using STO security scanners.
harness/harness-skills
Generate Harness Agent Template files for AI-powered automation agents.
Works with
Categories
Add an Artifact Signing (SscaArtifactSigning) step to an existing Harness pipeline to Cosign-sign container or local-stage artifacts with keyless, key-based, or Vault signing. Sign Artifact is an agent skill from harness/harness-skills. Add an Artifact Signing (SscaArtifactSigning) step to an existing Harness pipeline to Cosign-sign container or local-stage artifacts with keyless, key-based, or Vault signing.
Sign Artifact fits situations like: asked to sign artifacts; add artifact signing; cosign sign image; attach signature to registry.
Run `npx skills add harness/harness-skills --skill sign-artifact -a claude-code`. Or copy the skill folder (skills/sign-artifact in harness/harness-skills) into .claude/skills/sign-artifact in your project. Claude Code loads it when a task matches its description.
Run `npx skills add harness/harness-skills --skill sign-artifact -a codex`. Or copy the skill folder (skills/sign-artifact in harness/harness-skills) into .agents/skills/sign-artifact in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add harness/harness-skills --skill sign-artifact -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sign-artifact, .gemini/skills/sign-artifact, .github/skills/sign-artifact and .opencode/skills/sign-artifact in your project.
SKILL.md names no scripts, command-line tools or credentials: Sign Artifact is instructions for the agent only. Our summary lists: Docker. Compatibility (from SKILL.md): Requires Harness MCP v2 server (harness-mcp-v2).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Sign Artifact is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.6k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.8k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Sign Artifact: Iron Proxy Gateway for NanoClaw (nanocoai/nanoclaw, 31k stars), GreptimeDB Dev Docker Image (GreptimeTeam/greptimedb, 6.7k stars), Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars) and LangBot Deployment Guide (langbot-app/LangBot, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
harness (a GitHub organization) maintains it in harness/harness-skills, which has 115 GitHub stars. The repository holds 24 skills in this directory. The repository was last updated on October 6, 2026.
Source: harness/harness-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.