Agent skill

Verify Sign

by harness in harness/harness-skills

Add an Artifact Verification (SscaArtifactVerification) step to an existing Harness pipeline to verify Cosign signatures on container or local-stage artifacts.

Apache-2.0Auto-check passedDevOps & Cloud

Install Verify Sign

skills CLI
$ npx skills add harness/harness-skills --skill verify-sign -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install harness/harness-skills verify-sign --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/harness/harness-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/verify-sign .claude/skills/verify-sign && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
verify-sign
GitHub stars
115
Token cost
~4.5k tokens
SKILL.md length
1,465 words
Files
4 (incl. references)
Skills in repo
24
Repo updated
First seen
Licence
Apache-2.0

At a glance

Add an Artifact Verification (SscaArtifactVerification) step to an existing Harness pipeline to verify Cosign signatures on container or local-stage artifacts.

  • Works in 12 steps: One question per turn — use AskQuestion… → Opening message — add Artifact… → Progress breadcrumb — after pipeline fetch → …
  • Asked to verify signed artifacts
  • SKILL.md covers Interaction model (mandatory), Instructions, Examples and Performance Notes, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Verify Sign is an agent skill from harness/harness-skills. Add an Artifact Verification (SscaArtifactVerification) step to an existing Harness pipeline to verify Cosign signatures on container or local-stage artifacts. Supports CI, Security, and CD Deploy (containerized step group). Supports Third-Party registries (Docker, ECR, GCR, GAR, ACR), Harness Artifact Registry (HAR), and Harness Local Stage artifacts. Only works with existing pipelines. Use when asked to verify signed artifacts, verify artifact signature, verify-sign, validate Cosign signature, or configure…

Its SKILL.md is about 4.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/artifact-verification-step.md`, `references/cd-containerized-step-group.md` and `references/interactive-wizard-flow.md`). Compatibility notes: Requires Harness MCP v2 server (harness-mcp-v2)

It sits in DevOps & Cloud. It works with Docker. The repository describes itself as: A collection of structured AI agent skills that enable Claude Code, Cursor, GitHub Copilot, and other AI coding assistants to create, operate, debug, and govern Harness CI/CD… The licence is Apache-2.0.

When your agent uses it

  • Asked to verify signed artifacts
  • Verify artifact signature
  • Validate Cosign signature
  • Configure SscaArtifactVerification

Example prompts

  • “/verify-sign”

Requirements

  • Docker
  • Compatibility (from SKILL.md): Requires Harness MCP v2 server (harness-mcp-v2)

Workflow steps

12 steps, taken from the first numbered list in SKILL.md.

  1. One question per turn — use AskQuestion when available; otherwise numbered options with (Recommended).
  2. Opening message — add Artifact Verification; mention signing prerequisite + HAR support.
  3. Progress breadcrumb — after pipeline fetch
  4. Record answers — running summary; do not re-ask unless the user changes direction.
  5. Fetch before configure — harness_get before placement/source questions.
  6. Show pipeline structure — highlight SscaArtifactSigning and connectors.
  7. Infer source from signing — when one SscaArtifactSigning step exists, reuse its source. If
  8. Never guess image tags — default from signing step; ask if ambiguous.
  9. Confirm before write — summary + harness_update only after user confirms.
  10. Stop after update — after successful harness_update, provide a configuration summary and
  11. CD on CI-only pipeline — do not reject CD verify; run Phase 3b to add Deploy stage + containerized group.
  12. Verify method must match signing — keyless ↔ keyless, keybased/cosign ↔ public key from same key pair.

What it can do on your machine

Read from SKILL.md and the folder at commit c25faee. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are yaml).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires Harness MCP v2 server (harness-mcp-v2)

    From compatibility in the SKILL.md frontmatter.

Context cost

Verify Sign loads about 4.5k tokens when it runs, and up to ~8.8k if it reads all its reference files. Until then it costs about 183 tokens; SKILL.md has 1,465 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~183
When it runs · the whole SKILL.md, loaded when a task matches
~4.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from harness/harness-skills at commit c25faee, republished under its Apache-2.0 licence (© harness). 1,465 words, ~4,462 tokens.

Download SKILL.mdSave it as .claude/skills/verify-sign/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
verify-sign
description
Add an Artifact Verification (SscaArtifactVerification) step to an existing Harness pipeline to verify Cosign signatures on container or local-stage artifacts. Supports CI, Security, and CD Deploy (containerized step group). Supports Third-Party registries (Docker, ECR, GCR, GAR, ACR), Harness Artifact Registry (HAR), and Harness Local Stage artifacts. Only works with existing pipelines. Use when asked to verify signed artifacts, verify artifact signature, verify-sign, validate Cosign signature, or configure SscaArtifactVerification. Trigger phrases: verify sign, verify artifact, artifact verification, verify signature, verify-sign, SscaArtifactVerification, verify signed image, verify Cosign, HAR verification.
compatibility
Requires Harness MCP v2 server (harness-mcp-v2)
metadata.author
Harness
metadata.version
1.0.0
metadata.mcp-server
harness-mcp-v2
license
Apache-2.0

Verify Sign

Add an Artifact Verification (SscaArtifactVerification) step to an existing Harness pipeline. The step verifies Cosign signatures on artifacts — typically immediately after SscaArtifactSigning.

This skill only works with existing pipelines — do not create standalone verification-only pipelines.

Prerequisites: Artifact must already be signed (typically via /sign-artifact / SscaArtifactSigning). Key-based verify requires the Cosign public key file secret matching the signing private key (/create-secret). If signing did not upload .sig to the registry, Harness pulls the signature from its database during verification.

Supported stages: CI, Security, and CD (Deployment in containerized step group before deploy).

Guide the user through a step-by-step interactive wizard (same UX as /sign-artifact):

  • Wizard: references/interactive-wizard-flow.md
  • UI ↔ YAML: references/artifact-verification-step.md
  • CD containerized step groups: references/cd-containerized-step-group.md

Interaction model (mandatory)

  1. One question per turn — use AskQuestion when available; otherwise numbered options with (Recommended).
  2. Opening message — add Artifact Verification; mention signing prerequisite + HAR support.
  3. Progress breadcrumb — after pipeline fetch: Pipeline · Placement · Source · Details · Verify · Submit
  4. Record answers — running summary; do not re-ask unless the user changes direction.
  5. Fetch before configure — harness_get before placement/source questions.
  6. Show pipeline structure — highlight SscaArtifactSigning and connectors.
  7. Infer source from signing — when one SscaArtifactSigning step exists, reuse its source. If multiple exist, ask which step to mirror.
  8. Never guess image tags — default from signing step; ask if ambiguous.
  9. Confirm before write — summary + harness_update only after user confirms.
  10. Stop after update — after successful harness_update, provide a configuration summary and point the user to /run-pipeline to execute. Do not call harness_execute, poll executions, or run harness_diagnose in this skill (same pattern as /configure-repo-scan).
  11. CD on CI-only pipeline — do not reject CD verify; run Phase 3b to add Deploy stage + containerized group.
  12. Verify method must match signing — keyless ↔ keyless, keybased/cosign ↔ public key from same key pair.
  13. Offer all three source tiles — Third-Party, HAR, and Harness Local Stage.
  14. List all connectors in Phase 6 — same rules as /sign-artifact: harness_list with filters.type, all scopes, size: 100, paginate; never hand-pick a subset. See wizard Phase 6.
  15. List all infrastructure in Phase 3b — harness_list per environment with filters.environment_id; never show only the infra for one pre-selected environment.
  16. CD image defaults to <+artifact.image> — for Deploy-stage verify, recommend the service artifact expression over a static tag from signing. Warn when static image ≠ service default tag.
  17. Preflight delegates before CD update — harness_list(resource_type="delegate") or harness_execute(test_connection) on the K8s connector used in stepGroupInfra. Abort or warn if DELEGATE_NOT_AVAILABLE is likely (connector has delegateSelectors with no active delegate).
  18. CD Deploy stage YAML requirements — new Deploy stages need failureStrategies: StageRollback, rollbackSteps with K8sRollingRollback + spec: {}, and CI stages need MarkAsFailure when missing. See references/cd-containerized-step-group.md.

Full phase prompts: references/interactive-wizard-flow.md.


Instructions

Wizard phases
PhaseBreadcrumbAction
0PipelineAskQuestion: pipeline URL ready?
1PipelineCollect URL → harness_get
2PipelineDisplay structure; note missing SscaArtifactSigning
3PlacementAskQuestion: after signing, CD before deploy, etc.
3bPlacement (CD)Service, env, infra, step group if new Deploy stage
4SourceInfer from signing or pick registry tile
5SourceRegistry provider (Third-Party only)
6DetailsConnector — list all via harness_list + filters.type (skip if obvious)
7DetailsImage / artifact fields (default from signing)
8VerifyAskQuestion: verify signature method
9SubmitAskQuestion: confirm pipeline update

After Phase 9 confirm → insert step, harness_update, then provide summary (do not run the pipeline).

Supported stage types
Stage typeStep typePlacement notes
CISscaArtifactVerificationAfter SscaArtifactSigning in the same stage
DeploymentSscaArtifactVerificationContainerized step group; before deploy
SecuritySscaArtifactVerificationAfter signing when artifact is in registry
CD edge case

If no Deployment stage and user chose CD verify:

No CD Deploy stage yet. We can add a Deployment stage with a containerized step group and place Artifact Verification before deploy.

Run Phase 3b (service, environment, infrastructure, stepGroupInfra) — see references/cd-containerized-step-group.md.

Preflight before CD stage write
  1. harness_get the K8s connector used in stepGroupInfra — note delegateSelectors.
  2. harness_list(resource_type="delegate") — confirm an active delegate matches required selectors (e.g. ssca-prod2-at). Warn before harness_update if none match.
  3. harness_get(resource_type="service") — note primary artifact tag; if user chose a static verify image, warn when it differs from the service default.
CD Deploy stage YAML (append to pipeline)

When adding a new Deploy stage, include all required blocks (API rejects incomplete YAML):

yaml
    - stage:
        name: Deploy
        identifier: Deploy
        type: Deployment
        spec:
          deploymentType: Kubernetes
          service:
            serviceRef: <service_id>
          environment:
            environmentRef: <env_id>
            infrastructureDefinitions:
              - identifier: <infra_id>
          execution:
            steps:
              - stepGroup:
                  identifier: scs_before_deploy
                  name: Supply Chain Security
                  stepGroupInfra:
                    type: KubernetesDirect
                    spec:
                      connectorRef: <k8s_connector>
                      namespace: <namespace>
                  steps:
                    - step:
                        identifier: artifactverification_cd
                        name: Artifact Verification
                        type: SscaArtifactVerification
                        spec:
                          source:
                            type: docker
                            spec:
                              connector: <registry_connector>
                              image: <+artifact.image>
                          verifySign:
                            type: keyless
                            spec:
                              oidcProvider: harness
                        timeout: 15m
              - step:
                  identifier: rolling_deployment
                  name: Rolling Deployment
                  type: K8sRollingDeploy
                  spec:
                    skipDryRun: false
                  timeout: 10m
            rollbackSteps:
              - step:
                  identifier: rollback
                  name: Rollback
                  type: K8sRollingRollback
                  spec: {}
                  timeout: 10m
        failureStrategies:
          - onFailure:
              errors: [AllErrors]
              action:
                type: StageRollback

Also ensure existing CI stages have failureStrategies: MarkAsFailure when missing.

Check prerequisites
  1. Artifact signing — pipeline contains SscaArtifactSigning (or user confirms signature exists).
  2. Public key secret (key-based) — file secret with Cosign public key matching signing private key.
Extract context from pipeline YAML

From SscaArtifactSigning (if present), copy source and map signing → verification:

SigningVerification
source.type: dockersame source.type: docker
source.spec.imagesame source.spec.image
source.spec.connectorsame source.spec.connector
source.type: harsame source.type: har + registry + image
signing.type: keylessverifySign keyless (match OIDC provider)
signing.type: cosign / keybasedverifySign with public key secret
Generate Artifact Verification step YAML

CI — Docker Registry, key-based verify (Harness docs):

yaml
- step:
    identifier: artifactverification
    name: Artifact Verification
    type: SscaArtifactVerification
    spec:
      source:
        type: docker
        spec:
          connector: lavakush07
          image: lavakush07/easy-buggy-app:v5
      verifySign:
        type: cosign
        spec:
          public_key: account.cosign_public_key
    timeout: 15m

Keyless verify (when signing used keyless Harness OIDC):

yaml
      verifySign:
        type: keyless
        spec:
          oidcProvider: harness

If API validation rejects flat keyless, retry nested cosign wrapper — see references/artifact-verification-step.md.

HAR verify:

yaml
      source:
        type: har
        spec:
          registry: prod_har
          image: my-service:v3

CD Deploy — same step type inside containerized stepGroup; use <+artifact.image> for image when verifying service artifacts.

Full provider mapping: references/artifact-verification-step.md.

Insert step into pipeline YAML

Critical: Use the exact yamlPipeline from harness_get as the base. Insert or update only SscaArtifactVerification (and CD step group infra when applicable). Never add HarnessSAST, STO scanners, or other steps — signing/verification skills do not configure code scan.

  • Insert at Phase 3 placement — after artifactsigning when possible.
  • Do not modify unrelated steps.
  • Step identifier: artifactverification (use artifactverification_cd in CD when CI already has one).
  • CD: inside containerized step group only.
Show full SKILL.md (551 more words)Show less
Update pipeline via MCP
harness_update
  resource_type: pipeline
  resource_id: <pipeline_identifier>
  org_id: <organization>
  project_id: <project>
  body: { yamlPipeline: "<updated pipeline YAML>" }

On validation errors, check verifySign shape, image field, and public key secret refs.

Provide summary

Report the results to the user (same pattern as /configure-repo-scan — do not execute the pipeline):

## Artifact Verification Configured

**Pipeline:** <pipeline_name>
**Step:** Artifact Verification (SscaArtifactVerification)
**Location:** Stage "<stage_name>", <position>
**Source:** docker — <connector> — <image>
**Verify signature:** Keyless (Harness OIDC) — or as configured

**Pipeline URL:** https://app.harness.io/ng/account/<account_id>/module/ci/orgs/<org_id>/projects/<project_id>/pipelines/<pipeline_id>/pipeline-studio/

**Note:** Review the Artifact Verification step in Pipeline Studio to adjust Advanced settings.

### Next Steps
1. Run the pipeline via `/run-pipeline` to verify artifact verification executes successfully
2. If the run fails, diagnose with `/debug-pipeline`
3. View verification outcome on the execution **Supply Chain** tab
4. If **Failed**, confirm verify method matches signing; check public key for keybased
5. Add signing with `/sign-artifact` if signature was missing — ensure `uploadSignature.upload: true`
6. Add SBOM/SLSA if not present (`/manage-supply-chain` or pipeline `SscaOrchestration` / `provenance`)
7. Automate with `/create-trigger`

CD pipelines: note in the summary if runtime inputs (service artifact, environment, infrastructure, artifact tag/digest) will be required at run time — the user provides those via /run-pipeline or Harness UI Run. When running CI+CD, check runtime_input_template — service primaryArtifactRef: <+input> may need artifact tag/digest in inputs even when the template only shows build.


Examples

Verify after Artifact Signing
/verify-sign
Add artifact verification after artifactsigning — public key account.cosign_public_key
CD before deploy
/verify-sign
Verify signed artifact in deploy stage before K8s rolling deploy — keyless verify
HAR verification
/verify-sign
Verify signature for HAR image payment-service:v2 — same registry as signing step
Keyless verify (matches keyless signing)
/verify-sign
Verify with keyless Harness OIDC — same image as signing step

Performance Notes

  • Only existing pipelines (may append Deploy stage).
  • Wizard UX mandatory — one question per turn.
  • Reuse signing source — same lowercase source.type and image as SscaArtifactSigning.
  • Field is verifySign (camelCase) — not verify_attestation (SLSA) or signing.
  • HAR is a first-class source — source.type: har; offer even if UI shows only two tiles.
  • CD verification supported — containerized step group only; signing in Deploy is not supported.
  • Do not execute pipelines in this skill — use /run-pipeline after configuration (same as /configure-repo-scan).
  • Pair with /sign-artifact (sign) — verify method must match signing.

Troubleshooting

No Artifact Signing Step
  • Add /sign-artifact first with signature upload or Harness DB signature storage.
  • Scan for SscaArtifactSigning or identifier: artifactsigning.
Signature Verification Failed
  • Verify method must match signing (keyless vs keybased/cosign).
  • Keybased: use public key secret (signing uses private key).
  • If .sig not in registry, signing step may not have set uploadSignature.upload: true (Harness default is unchecked). Update signing step and re-run, or rely on Harness DB signature storage.
Multiple Signing Steps
  • Ask user which SscaArtifactSigning step to mirror for source, image, and verify method.
Vault Verify Failed
  • Confirm Vault connector and public key path match the signing secret-manager block.
Wrong Image
  • CI: use same image as signing step source.spec.image.
  • CD: default to <+artifact.image> — static signing tag (e.g. :v5) may not match service artifact (e.g. :v24) and verification will fail or verify the wrong image.
CD Deploy Failed — No Delegate (DELEGATE_NOT_AVAILABLE)
  • Symptom: Deploy fails immediately; message mentions missing delegate or selector mismatch (e.g. Delegate(s) don't have selectors [ssca-prod2-at]).
  • Fix: start a delegate with matching selectors (/manage-delegates), or pick infra/K8s connector backed by an active delegate. Re-run after delegate is healthy.
CD YAML Validation Errors (new Deploy stage)
  • failureStrategies: is missing — add StageRollback on the Deploy stage.
  • rollbackSteps[0].step.spec: is missing — K8sRollingRollback requires spec: {}.
  • See full template in references/cd-containerized-step-group.md.
YAML Validation Errors
  • Step type must be SscaArtifactVerification.
  • Docker source requires connector + image (not repo or image_path).
  • verifySign: prefer flat type: keyless; keybased uses type: cosign + public_key.
  • DUPLICATE_IDENTIFIER — rename artifactverification.
CD Step Errors
  • Place inside stepGroup with stepGroupInfra — not top-level execution.steps.
  • See references/cd-containerized-step-group.md.
User Chose CD on CI-Only Pipeline
  • Expected — run Phase 3b; do not force CI-only unless user changes direction.
Incomplete connector / infrastructure list
  • Use harness_list + filters: { type: "DockerRegistry" } (not harness_search or params.filterType). Query project, org, and account scopes. For infrastructure, list per environment with filters: { environment_id: "<env>" } — see wizard Phase 3b and Phase 6.
Pipeline Run Failed
  • Use /run-pipeline to execute and /debug-pipeline to diagnose failures
  • Missing runtime inputs: provide branch/tag, artifact tag/digest, or deploy inputs via /run-pipeline or Harness UI Run
MCP Errors
  • CONNECTOR_NOT_FOUND — verify connector in Project Settings; re-run scoped harness_list.
  • ACCESS_DENIED — PAT needs pipeline edit permission.
  • harness_update timeout — retry once; provide YAML for manual paste if MCP keeps timing out.

© harness, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in skills/verify-sign of harness/harness-skills.

  • SKILL.md
  • references/artifact-verification-step.md
  • references/cd-containerized-step-group.md
  • references/interactive-wizard-flow.md

Open the folder on GitHubat commit c25faee

Compare with similar skills

Verify Sign next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Verify Sign compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Verify Sign this skillharness/harness-skills115—~4.5kAutomated safety check: PassApache-2.0
Iron Proxy Gateway for NanoClawnanocoai/nanoclaw31k—~4.6kAutomated safety check: NotesMIT
GreptimeDB Dev Docker ImageGreptimeTeam/greptimedb6.7k—~4kAutomated safety check: NotesApache-2.0
Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit2606 repos~1.1kAutomated safety check: NotesCustom licence
LangBot Deployment Guidelangbot-app/LangBot18k—~1.2kAutomated safety check: NotesApache-2.0
Build Openshell Mxc WindowsNVIDIA/OpenShell16k—~4.9kAutomated safety check: PassApache-2.0

Similar skills

  • Installs or refreshes Iron Proxy and its Iron Control web console for NanoClaw, with a local Docker setup, database, credentials and a human approval bridge.

    31k GitHub stars~4.6k tokensUpdated 3 days ago
    DevOps & CloudAuto-check: notes
  • GreptimeDB Dev Docker Image

    GreptimeTeam/greptimedb

    Packages a locally built GreptimeDB debug binary into a development-only Docker image for local-cluster testing, with an optional push to a dev registry.

    6.7k GitHub stars~4k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    260 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes
  • LangBot Deployment Guide

    langbot-app/LangBot

    Deploys and configures a LangBot instance with Docker Compose or Kubernetes, covering config.yaml, the Box sandbox runtime, the plugin runtime and the global API key.

    18k GitHub stars~1.2k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Official

    Maintain and validate OpenShell's build-only Windows MSVC lane for x64 and ARM64.

    16k GitHub stars~4.9k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Megatron-LM Base Image Bump

    NVIDIA/Megatron-LM

    Official

    Moves Megatron-LM CI to a newer NVIDIA PyTorch base image, updating both the GitHub and GitLab pins together and handling the CI follow-up.

    18k GitHub stars~2.8k tokensUpdated today
    DevOps & CloudAuto-check passed

More from harness/harness-skills

All 24 skills in this repo
  • Audit Report

    harness/harness-skills

    Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.

    115 GitHub stars~1.3k tokensUpdated 2 days ago
    Auto-check passed
  • Chaos Dr Test

    harness/harness-skills

    A skill your agent uses when working with Chaos Engineering steps inside a Harness pipeline.

    115 GitHub stars~2.6k tokensUpdated 2 days ago
    Auto-check passed
  • Chaos Experiment

    harness/harness-skills

    A skill your agent uses when the user asks to create, edit, update, design, or configure a Harness Chaos Experiment — including faults, probes, actions, experiment YAML, fault injection, pod-delete…

    115 GitHub stars~1.6k tokensUpdated 2 days ago
    Auto-check passed
  • Cleanup Feature Flags

    harness/harness-skills

    Remove a launched Harness FME feature flag from application code, keeping the treatment FME serves today, and open a pull request.

    115 GitHub stars~2.4k tokensUpdated 2 days ago
    Auto-check passed
  • Configure Repo Scan

    harness/harness-skills

    Configure code scanning in Harness pipelines using STO security scanners.

    115 GitHub stars~2.2k tokensUpdated 2 days ago
    Auto-check passed
  • Create Agent Template

    harness/harness-skills

    Generate Harness Agent Template files for AI-powered automation agents.

    115 GitHub stars~2.2k tokensUpdated 2 days ago
    Auto-check passed

Works with

Categories

Questions about Verify Sign

What does Verify Sign do?

Add an Artifact Verification (SscaArtifactVerification) step to an existing Harness pipeline to verify Cosign signatures on container or local-stage artifacts. Verify Sign is an agent skill from harness/harness-skills. Add an Artifact Verification (SscaArtifactVerification) step to an existing Harness pipeline to verify Cosign signatures on container or local-stage artifacts.

When should I use Verify Sign?

Verify Sign fits situations like: asked to verify signed artifacts; verify artifact signature; validate Cosign signature; configure SscaArtifactVerification.

How do I install Verify Sign in Claude Code?

Run `npx skills add harness/harness-skills --skill verify-sign -a claude-code`. Or copy the skill folder (skills/verify-sign in harness/harness-skills) into .claude/skills/verify-sign in your project. Claude Code loads it when a task matches its description.

How do I install Verify Sign in Codex?

Run `npx skills add harness/harness-skills --skill verify-sign -a codex`. Or copy the skill folder (skills/verify-sign in harness/harness-skills) into .agents/skills/verify-sign in your project. Codex loads it when a task matches its description.

Can I use Verify Sign in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add harness/harness-skills --skill verify-sign -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/verify-sign, .gemini/skills/verify-sign, .github/skills/verify-sign and .opencode/skills/verify-sign in your project.

What does Verify Sign need to run?

SKILL.md names no scripts, command-line tools or credentials: Verify Sign is instructions for the agent only. Our summary lists: Docker. Compatibility (from SKILL.md): Requires Harness MCP v2 server (harness-mcp-v2).

Does Verify Sign access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Verify Sign safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Verify Sign use?

Verify Sign is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Verify Sign use?

About 4.5k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.3k tokens, read only when the agent opens those files.

What are the alternatives to Verify Sign?

Skills that share tags, products or a category with Verify Sign: Iron Proxy Gateway for NanoClaw (nanocoai/nanoclaw, 31k stars), GreptimeDB Dev Docker Image (GreptimeTeam/greptimedb, 6.7k stars), Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars) and LangBot Deployment Guide (langbot-app/LangBot, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Verify Sign?

harness (a GitHub organization) maintains it in harness/harness-skills, which has 115 GitHub stars. The repository holds 24 skills in this directory. The repository was last updated on October 6, 2026.

Source: harness/harness-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.