Iron Proxy Gateway for NanoClaw
nanocoai/nanoclaw
Installs or refreshes Iron Proxy and its Iron Control web console for NanoClaw, with a local Docker setup, database, credentials and a human approval bridge.
Add an Artifact Verification (SscaArtifactVerification) step to an existing Harness pipeline to verify Cosign signatures on container or local-stage artifacts.
$ npx skills add harness/harness-skills --skill verify-sign -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install harness/harness-skills verify-sign --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/harness/harness-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/verify-sign .claude/skills/verify-sign && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "verify-sign" agent skill from https://github.com/harness/harness-skills/tree/main/skills/verify-sign into .claude/skills/verify-sign/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verify-sign", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/harness/harness-skills/tree/main/skills/verify-signType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add harness/harness-skills --skill verify-sign -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install harness/harness-skills verify-sign --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/harness/harness-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/verify-sign .agents/skills/verify-sign && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "verify-sign" agent skill from https://github.com/harness/harness-skills/tree/main/skills/verify-sign into .agents/skills/verify-sign/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verify-sign", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add harness/harness-skills --skill verify-sign -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install harness/harness-skills verify-sign --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/harness/harness-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/verify-sign .cursor/skills/verify-sign && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "verify-sign" agent skill from https://github.com/harness/harness-skills/tree/main/skills/verify-sign into .cursor/skills/verify-sign/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verify-sign", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/harness/harness-skills.git --path skills/verify-sign--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add harness/harness-skills --skill verify-sign -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install harness/harness-skills verify-sign --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/harness/harness-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/verify-sign .gemini/skills/verify-sign && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "verify-sign" agent skill from https://github.com/harness/harness-skills/tree/main/skills/verify-sign into .gemini/skills/verify-sign/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verify-sign", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install harness/harness-skills verify-signInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add harness/harness-skills --skill verify-sign -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/harness/harness-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/verify-sign .github/skills/verify-sign && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "verify-sign" agent skill from https://github.com/harness/harness-skills/tree/main/skills/verify-sign into .github/skills/verify-sign/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verify-sign", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add harness/harness-skills --skill verify-sign -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install harness/harness-skills verify-sign --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/harness/harness-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/verify-sign .opencode/skills/verify-sign && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "verify-sign" agent skill from https://github.com/harness/harness-skills/tree/main/skills/verify-sign into .opencode/skills/verify-sign/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verify-sign", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
verify-signAdd an Artifact Verification (SscaArtifactVerification) step to an existing Harness pipeline to verify Cosign signatures on container or local-stage artifacts.
Verify Sign is an agent skill from harness/harness-skills. Add an Artifact Verification (SscaArtifactVerification) step to an existing Harness pipeline to verify Cosign signatures on container or local-stage artifacts. Supports CI, Security, and CD Deploy (containerized step group). Supports Third-Party registries (Docker, ECR, GCR, GAR, ACR), Harness Artifact Registry (HAR), and Harness Local Stage artifacts. Only works with existing pipelines. Use when asked to verify signed artifacts, verify artifact signature, verify-sign, validate Cosign signature, or configure…
Its SKILL.md is about 4.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/artifact-verification-step.md`, `references/cd-containerized-step-group.md` and `references/interactive-wizard-flow.md`). Compatibility notes: Requires Harness MCP v2 server (harness-mcp-v2)
It sits in DevOps & Cloud. It works with Docker. The repository describes itself as: A collection of structured AI agent skills that enable Claude Code, Cursor, GitHub Copilot, and other AI coding assistants to create, operate, debug, and govern Harness CI/CD… The licence is Apache-2.0.
12 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit c25faee. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are yaml).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Requires Harness MCP v2 server (harness-mcp-v2)
From compatibility in the SKILL.md frontmatter.
Verify Sign loads about 4.5k tokens when it runs, and up to ~8.8k if it reads all its reference files. Until then it costs about 183 tokens; SKILL.md has 1,465 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from harness/harness-skills at commit c25faee, republished under its Apache-2.0 licence (© harness). 1,465 words, ~4,462 tokens.
.claude/skills/verify-sign/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Add an Artifact Verification (SscaArtifactVerification) step to an existing Harness pipeline.
The step verifies Cosign signatures on artifacts — typically immediately after SscaArtifactSigning.
This skill only works with existing pipelines — do not create standalone verification-only pipelines.
Prerequisites: Artifact must already be signed (typically via /sign-artifact /
SscaArtifactSigning). Key-based verify requires the Cosign public key file secret matching the
signing private key (/create-secret). If signing did not upload .sig to the registry, Harness
pulls the signature from its database during verification.
Supported stages: CI, Security, and CD (Deployment in containerized step group before deploy).
Guide the user through a step-by-step interactive wizard (same UX as /sign-artifact):
references/interactive-wizard-flow.mdreferences/artifact-verification-step.mdreferences/cd-containerized-step-group.mdAskQuestion when available; otherwise numbered options with (Recommended).Pipeline · Placement · Source · Details · Verify · Submitharness_get before placement/source questions.SscaArtifactSigning and connectors.SscaArtifactSigning step exists, reuse its source. If
multiple exist, ask which step to mirror.harness_update only after user confirms.harness_update, provide a configuration summary and
point the user to /run-pipeline to execute. Do not call harness_execute, poll
executions, or run harness_diagnose in this skill (same pattern as /configure-repo-scan)./sign-artifact: harness_list with
filters.type, all scopes, size: 100, paginate; never hand-pick a subset. See wizard Phase 6.harness_list per environment with
filters.environment_id; never show only the infra for one pre-selected environment.<+artifact.image> — for Deploy-stage verify, recommend the service
artifact expression over a static tag from signing. Warn when static image ≠ service default tag.harness_list(resource_type="delegate") or
harness_execute(test_connection) on the K8s connector used in stepGroupInfra. Abort or warn if
DELEGATE_NOT_AVAILABLE is likely (connector has delegateSelectors with no active delegate).failureStrategies: StageRollback,
rollbackSteps with K8sRollingRollback + spec: {}, and CI stages need MarkAsFailure when
missing. See references/cd-containerized-step-group.md.Full phase prompts: references/interactive-wizard-flow.md.
| Phase | Breadcrumb | Action |
|---|---|---|
| 0 | Pipeline | AskQuestion: pipeline URL ready? |
| 1 | Pipeline | Collect URL → harness_get |
| 2 | Pipeline | Display structure; note missing SscaArtifactSigning |
| 3 | Placement | AskQuestion: after signing, CD before deploy, etc. |
| 3b | Placement (CD) | Service, env, infra, step group if new Deploy stage |
| 4 | Source | Infer from signing or pick registry tile |
| 5 | Source | Registry provider (Third-Party only) |
| 6 | Details | Connector — list all via harness_list + filters.type (skip if obvious) |
| 7 | Details | Image / artifact fields (default from signing) |
| 8 | Verify | AskQuestion: verify signature method |
| 9 | Submit | AskQuestion: confirm pipeline update |
After Phase 9 confirm → insert step, harness_update, then provide summary (do not run the pipeline).
| Stage type | Step type | Placement notes |
|---|---|---|
CI | SscaArtifactVerification | After SscaArtifactSigning in the same stage |
Deployment | SscaArtifactVerification | Containerized step group; before deploy |
Security | SscaArtifactVerification | After signing when artifact is in registry |
If no Deployment stage and user chose CD verify:
No CD Deploy stage yet. We can add a Deployment stage with a containerized step group and place Artifact Verification before deploy.
Run Phase 3b (service, environment, infrastructure, stepGroupInfra) — see
references/cd-containerized-step-group.md.
harness_get the K8s connector used in stepGroupInfra — note delegateSelectors.harness_list(resource_type="delegate") — confirm an active delegate matches required
selectors (e.g. ssca-prod2-at). Warn before harness_update if none match.harness_get(resource_type="service") — note primary artifact tag; if user chose a static
verify image, warn when it differs from the service default.When adding a new Deploy stage, include all required blocks (API rejects incomplete YAML):
- stage:
name: Deploy
identifier: Deploy
type: Deployment
spec:
deploymentType: Kubernetes
service:
serviceRef: <service_id>
environment:
environmentRef: <env_id>
infrastructureDefinitions:
- identifier: <infra_id>
execution:
steps:
- stepGroup:
identifier: scs_before_deploy
name: Supply Chain Security
stepGroupInfra:
type: KubernetesDirect
spec:
connectorRef: <k8s_connector>
namespace: <namespace>
steps:
- step:
identifier: artifactverification_cd
name: Artifact Verification
type: SscaArtifactVerification
spec:
source:
type: docker
spec:
connector: <registry_connector>
image: <+artifact.image>
verifySign:
type: keyless
spec:
oidcProvider: harness
timeout: 15m
- step:
identifier: rolling_deployment
name: Rolling Deployment
type: K8sRollingDeploy
spec:
skipDryRun: false
timeout: 10m
rollbackSteps:
- step:
identifier: rollback
name: Rollback
type: K8sRollingRollback
spec: {}
timeout: 10m
failureStrategies:
- onFailure:
errors: [AllErrors]
action:
type: StageRollbackAlso ensure existing CI stages have failureStrategies: MarkAsFailure when missing.
SscaArtifactSigning (or user confirms signature exists).From SscaArtifactSigning (if present), copy source and map signing → verification:
| Signing | Verification |
|---|---|
source.type: docker | same source.type: docker |
source.spec.image | same source.spec.image |
source.spec.connector | same source.spec.connector |
source.type: har | same source.type: har + registry + image |
signing.type: keyless | verifySign keyless (match OIDC provider) |
signing.type: cosign / keybased | verifySign with public key secret |
CI — Docker Registry, key-based verify (Harness docs):
- step:
identifier: artifactverification
name: Artifact Verification
type: SscaArtifactVerification
spec:
source:
type: docker
spec:
connector: lavakush07
image: lavakush07/easy-buggy-app:v5
verifySign:
type: cosign
spec:
public_key: account.cosign_public_key
timeout: 15mKeyless verify (when signing used keyless Harness OIDC):
verifySign:
type: keyless
spec:
oidcProvider: harnessIf API validation rejects flat keyless, retry nested cosign wrapper — see
references/artifact-verification-step.md.
HAR verify:
source:
type: har
spec:
registry: prod_har
image: my-service:v3CD Deploy — same step type inside containerized stepGroup; use <+artifact.image> for image
when verifying service artifacts.
Full provider mapping: references/artifact-verification-step.md.
Critical: Use the exact yamlPipeline from harness_get as the base. Insert or update only
SscaArtifactVerification (and CD step group infra when applicable). Never add HarnessSAST, STO
scanners, or other steps — signing/verification skills do not configure code scan.
artifactsigning when possible.artifactverification (use artifactverification_cd in CD when CI already has one).harness_update
resource_type: pipeline
resource_id: <pipeline_identifier>
org_id: <organization>
project_id: <project>
body: { yamlPipeline: "<updated pipeline YAML>" }On validation errors, check verifySign shape, image field, and public key secret refs.
Report the results to the user (same pattern as /configure-repo-scan — do not execute the pipeline):
## Artifact Verification Configured
**Pipeline:** <pipeline_name>
**Step:** Artifact Verification (SscaArtifactVerification)
**Location:** Stage "<stage_name>", <position>
**Source:** docker — <connector> — <image>
**Verify signature:** Keyless (Harness OIDC) — or as configured
**Pipeline URL:** https://app.harness.io/ng/account/<account_id>/module/ci/orgs/<org_id>/projects/<project_id>/pipelines/<pipeline_id>/pipeline-studio/
**Note:** Review the Artifact Verification step in Pipeline Studio to adjust Advanced settings.
### Next Steps
1. Run the pipeline via `/run-pipeline` to verify artifact verification executes successfully
2. If the run fails, diagnose with `/debug-pipeline`
3. View verification outcome on the execution **Supply Chain** tab
4. If **Failed**, confirm verify method matches signing; check public key for keybased
5. Add signing with `/sign-artifact` if signature was missing — ensure `uploadSignature.upload: true`
6. Add SBOM/SLSA if not present (`/manage-supply-chain` or pipeline `SscaOrchestration` / `provenance`)
7. Automate with `/create-trigger`CD pipelines: note in the summary if runtime inputs (service artifact, environment, infrastructure,
artifact tag/digest) will be required at run time — the user provides those via /run-pipeline or
Harness UI Run. When running CI+CD, check runtime_input_template — service primaryArtifactRef: <+input>
may need artifact tag/digest in inputs even when the template only shows build.
/verify-sign
Add artifact verification after artifactsigning — public key account.cosign_public_key/verify-sign
Verify signed artifact in deploy stage before K8s rolling deploy — keyless verify/verify-sign
Verify signature for HAR image payment-service:v2 — same registry as signing step/verify-sign
Verify with keyless Harness OIDC — same image as signing stepsource.type and image as SscaArtifactSigning.verifySign (camelCase) — not verify_attestation (SLSA) or signing.source.type: har; offer even if UI shows only two tiles./run-pipeline after configuration (same as /configure-repo-scan)./sign-artifact (sign) — verify method must match signing./sign-artifact first with signature upload or Harness DB signature storage.SscaArtifactSigning or identifier: artifactsigning.keyless vs keybased/cosign)..sig not in registry, signing step may not have set uploadSignature.upload: true (Harness
default is unchecked). Update signing step and re-run, or rely on Harness DB signature storage.SscaArtifactSigning step to mirror for source, image, and verify method.secret-manager block.image as signing step source.spec.image.<+artifact.image> — static signing tag (e.g. :v5) may not match service
artifact (e.g. :v24) and verification will fail or verify the wrong image.DELEGATE_NOT_AVAILABLE)Delegate(s) don't have selectors [ssca-prod2-at])./manage-delegates), or pick infra/K8s connector
backed by an active delegate. Re-run after delegate is healthy.failureStrategies: is missing — add StageRollback on the Deploy stage.rollbackSteps[0].step.spec: is missing — K8sRollingRollback requires spec: {}.references/cd-containerized-step-group.md.type must be SscaArtifactVerification.connector + image (not repo or image_path).verifySign: prefer flat type: keyless; keybased uses type: cosign + public_key.DUPLICATE_IDENTIFIER — rename artifactverification.stepGroup with stepGroupInfra — not top-level execution.steps.references/cd-containerized-step-group.md.harness_list + filters: { type: "DockerRegistry" } (not harness_search or
params.filterType). Query project, org, and account scopes. For infrastructure, list per
environment with filters: { environment_id: "<env>" } — see wizard Phase 3b and Phase 6./run-pipeline to execute and /debug-pipeline to diagnose failures/run-pipeline or Harness UI RunCONNECTOR_NOT_FOUND — verify connector in Project Settings; re-run scoped harness_list.ACCESS_DENIED — PAT needs pipeline edit permission.harness_update timeout — retry once; provide YAML for manual paste if MCP keeps timing out.© harness, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (references) in skills/verify-sign of harness/harness-skills.
Open the folder on GitHubat commit c25faee
Verify Sign next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Verify Sign this skillharness/harness-skills | 115 | — | ~4.5k | Automated safety check: Pass | Apache-2.0 | |
| Iron Proxy Gateway for NanoClawnanocoai/nanoclaw | 31k | — | ~4.6k | Automated safety check: Notes | MIT | |
| GreptimeDB Dev Docker ImageGreptimeTeam/greptimedb | 6.7k | — | ~4k | Automated safety check: Notes | Apache-2.0 | |
| Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit | 260 | 6 repos | ~1.1k | Automated safety check: Notes | Custom licence | |
| LangBot Deployment Guidelangbot-app/LangBot | 18k | — | ~1.2k | Automated safety check: Notes | Apache-2.0 | |
| Build Openshell Mxc WindowsNVIDIA/OpenShell | 16k | — | ~4.9k | Automated safety check: Pass | Apache-2.0 |
nanocoai/nanoclaw
Installs or refreshes Iron Proxy and its Iron Control web console for NanoClaw, with a local Docker setup, database, credentials and a human approval bridge.
GreptimeTeam/greptimedb
Packages a locally built GreptimeDB debug binary into a development-only Docker image for local-cluster testing, with an optional push to a dev registry.
maslennikov-ig/claude-code-orchestrator-kit
Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…
langbot-app/LangBot
Deploys and configures a LangBot instance with Docker Compose or Kubernetes, covering config.yaml, the Box sandbox runtime, the plugin runtime and the global API key.
NVIDIA/OpenShell
Maintain and validate OpenShell's build-only Windows MSVC lane for x64 and ARM64.
NVIDIA/Megatron-LM
Moves Megatron-LM CI to a newer NVIDIA PyTorch base image, updating both the GitHub and GitLab pins together and handling the CI follow-up.
harness/harness-skills
Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.
harness/harness-skills
A skill your agent uses when working with Chaos Engineering steps inside a Harness pipeline.
harness/harness-skills
A skill your agent uses when the user asks to create, edit, update, design, or configure a Harness Chaos Experiment — including faults, probes, actions, experiment YAML, fault injection, pod-delete…
harness/harness-skills
Remove a launched Harness FME feature flag from application code, keeping the treatment FME serves today, and open a pull request.
harness/harness-skills
Configure code scanning in Harness pipelines using STO security scanners.
harness/harness-skills
Generate Harness Agent Template files for AI-powered automation agents.
Works with
Categories
Add an Artifact Verification (SscaArtifactVerification) step to an existing Harness pipeline to verify Cosign signatures on container or local-stage artifacts. Verify Sign is an agent skill from harness/harness-skills. Add an Artifact Verification (SscaArtifactVerification) step to an existing Harness pipeline to verify Cosign signatures on container or local-stage artifacts.
Verify Sign fits situations like: asked to verify signed artifacts; verify artifact signature; validate Cosign signature; configure SscaArtifactVerification.
Run `npx skills add harness/harness-skills --skill verify-sign -a claude-code`. Or copy the skill folder (skills/verify-sign in harness/harness-skills) into .claude/skills/verify-sign in your project. Claude Code loads it when a task matches its description.
Run `npx skills add harness/harness-skills --skill verify-sign -a codex`. Or copy the skill folder (skills/verify-sign in harness/harness-skills) into .agents/skills/verify-sign in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add harness/harness-skills --skill verify-sign -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/verify-sign, .gemini/skills/verify-sign, .github/skills/verify-sign and .opencode/skills/verify-sign in your project.
SKILL.md names no scripts, command-line tools or credentials: Verify Sign is instructions for the agent only. Our summary lists: Docker. Compatibility (from SKILL.md): Requires Harness MCP v2 server (harness-mcp-v2).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Verify Sign is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.5k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.3k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Verify Sign: Iron Proxy Gateway for NanoClaw (nanocoai/nanoclaw, 31k stars), GreptimeDB Dev Docker Image (GreptimeTeam/greptimedb, 6.7k stars), Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars) and LangBot Deployment Guide (langbot-app/LangBot, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
harness (a GitHub organization) maintains it in harness/harness-skills, which has 115 GitHub stars. The repository holds 24 skills in this directory. The repository was last updated on October 6, 2026.
Source: harness/harness-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.