Agent skill

Harness

by iii-hq in iii-hq/workers

The durable agent turn loop — kick off a turn with harness::send, render it from session-manager transcript events, react to harness::turn-completed, with deny-by-default tool dispatch and…

Apache-2.0Auto-check passed

Install Harness

skills CLI
$ npx skills add iii-hq/workers --skill harness -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install iii-hq/workers harness --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/iii-hq/workers.git skills-src && mkdir -p .claude/skills && cp -r skills-src/harness/skills .claude/skills/harness && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
harness
GitHub stars
113
Token cost
~2.6k tokens
SKILL.md length
1,342 words
Files
2
Skills in repo
19
Repo updated
First seen
Licence
Apache-2.0

At a glance

The durable agent turn loop — kick off a turn with harness::send, render it from session-manager transcript events, react to harness::turn-completed, with deny-by-default tool dispatch and…

  • Works in 2 steps: Register a handler:… → Register the trigger
  • SKILL.md covers When to Use, Boundaries, Functions and Filesystem scope, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Harness is an agent skill from iii-hq/workers. The durable agent turn loop — kick off a turn with harness::send, render it from session-manager transcript events, react to harness::turn-completed, with deny-by-default tool dispatch and synchronous hook extension points for policy siblings.

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `orchestration.md`).

It works with React. The licence is Apache-2.0.

Example prompts

  • “/harness”

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. Register a handler: registerFunction('myapp::on-turn-done', handler).
  2. Register the trigger

What it can do on your machine

Read from SKILL.md and the folder at commit ebfe027. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are json and typescript).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Harness loads about 2.6k tokens when it runs. Until then it costs about 64 tokens; SKILL.md has 1,342 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~64
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from iii-hq/workers at commit ebfe027, republished under its Apache-2.0 licence (© iii-hq). 1,342 words, ~2,613 tokens.

Download SKILL.mdSave it as .claude/skills/harness/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
harness
description
The durable agent turn loop — kick off a turn with `harness::send`, render it from session-manager transcript events, react to `harness::turn-completed`, with deny-by-default tool dispatch and synchronous hook extension points for policy siblings.

harness

The harness is the durable turn loop that wires session-manager, llm-router, and context-manager into an agent. A consumer stays thin: it kicks off a turn, renders the conversation from the session transcript, and reacts to turn boundaries and human-gated calls. The harness streams the assistant message into the session as it generates, so you watch the session, not the harness — there is no agent::events stream, and harness::status is a point-in-time recovery read, not a render feed.

Every invocation is a trigger (iii.trigger({ function_id, payload })); there is no separate "call" verb. Tool dispatch is deny-by-default: a send with no options.functions.allow is a plain chat loop and every model-requested call is refused until you allow globs per send. Sessions are minted by the harness (s_<uuid>) or supplied by you; a send into a running turn folds in as steering (merged: true) instead of erroring, and a repeated idempotency_key returns the original turn without appending.

A session-creating send names a model, or only a provider: the harness then starts on that provider's declared default model (default_model in router::provider::list, checked against its live catalog; a provider that reports none fails the send as before). A new session that names neither thinking_level nor provider_options also starts on the provider's default_thinking_level; an explicit level wins, and later sends into the session inherit the prior turn's as usual. thinking_level is off, minimal, low, medium, high or xhigh; off is honoured only on models whose catalog entry says supports_thinking_off: true; elsewhere the fallback is the provider's own (most send their lowest effort and warn, Kimi ignores the level).

Prerequisites: session-manager (required — transcript store and change feed) and llm-router (required — generation and the model catalog) must be present. context-manager (token budgeting and compaction) is a soft dependency — absent it, the harness sends raw history. approval-gate (the human-in-the-loop gate) is optional; without it no call is held and every allowed call runs un-gated.

When to Use

  • Start or steer an agent turn and return immediately (harness::send).
  • Cancel an in-flight turn (harness::stop) or read coarse turn state for recovery and guards (harness::status).
  • Chain turns or react to outcomes by binding harness::turn-completed.
  • Drive a turn from an arbitrary inbound event (cron tick, webhook, sensor) by translating it into a harness::send.

Boundaries

  • Not a transcript feed. Render from session-manager's session::message-added / message-updated / status-changed (reconcile by revision); do not poll harness::status for content.
  • Not the approvals engine. The harness ships only the gate mechanics; the policy, decision RPCs (approval::resolve), inbox (approval::list-pending), and prompt triggers live in approval-gate.
  • Not a chain guard. options.max_turns bounds a single turn, not a send-completed-send loop; carry your own stop condition.
  • Do not trigger the internal functions (below) — they forge call ids and turn progress, so calling them out of band corrupts the turn record.
  • An in-run agent cannot start turns: send / run / turn / stop are denied to the model by policy. harness::spawn is the only turn-starter an agent calls directly, and it self-enforces depth, fan-out, and policy subsetting. The other path is event-driven: an agent binds engine::register_trigger straight to harness::spawn (see Reactive triggers), with the spawn spec in the registration metadata, and the engine spawns the sub-agent when the event fires.

Functions

Consumer-facing:

  • harness::send — ensure the session, persist the incoming message, and kick off a turn; returns fast or merges into a running turn (steering).
  • harness::stop — request cancellation of an in-flight turn; cascades to spawned children.
  • harness::status — read the current turn state for a session; null when no turn ever ran. For recovery and guards, not rendering.
  • harness::spawn — spawn a sub-agent in a child session. Model-facing (invoked through agent_trigger), not a consumer entry point.
  • harness::ask — put a decision with discrete options to the user as a clickable card (1–4 questions, 2–4 options each). Model-facing (invoked through agent_trigger) and answered by the turn loop itself: the turn ends on the question and the answer arrives as the user's next message. Refused in sub-agents, structured-output turns, and for a second ask in one step.

Internal — the harness drives these; never trigger them directly: harness::turn (the durable loop step), harness::function::trigger / harness::function::resolve (dispatch and parked-call settle), harness::sweep-pending (cron expiry), and harness::on-config-change (hot-reload).

Filesystem scope

options.metadata.fs_scope.root on a send is the session's working directory; a later send that omits fs_scope keeps it. The harness stamps a trusted fs_scope { root, grants, boundary } onto every shell::* / coder::* call and strips any the model supplies. boundary decides what root means to the ide worker:

  • workspace — coder::*, shell::fs::* and an exec cwd stay inside root plus the session's grants (harness::filesystem::grant).
  • configured_roots — root only anchors relative paths; the worker's own roots apply. The model's prompt says so ("default directory, not an access boundary").

The filesystem_boundary config picks it: auto (the default) is workspace only while approval-gate's access watch is bound; workspace or configured_roots pins it. harness::filesystem::info reports the boundary in effect. A sub-agent spawned in a turn into a new session starts with a copy of its parent's grants; later grants to the parent do not reach it. Under workspace, an in-turn spawn's options.filesystem_root must lie inside the parent's root or grants. What an exec'd process itself writes is the ide worker's fs.exec_confinement switch.

Show full SKILL.md (497 more words)Show less

Reactive triggers

The harness emits two async turn-boundary trigger types so consumers and siblings react without polling harness::status:

  • harness::turn-started — a turn began executing (first loop step).
  • harness::turn-completed — a turn reached a terminal status (completed / cancelled / failed), carrying the result or error for chaining, failure toasts, auto-titling, and result delivery.

Bind turn-completed for outcomes and to chain the next hop; bind turn-started only for observability. Delivery is fire-and-forget, at-least-once, and unordered — treat each event as an edge. Nothing replays on reconnect: re-seed with harness::status and approval::list-pending, then rebind. Do not bind these for live transcript rendering — that is session-manager's job.

Binding config filters delivery by session_id, or by parent_session_id to watch the children a turn spawns (in-turn spawns only — a direct harness::spawn call creates no parent link, so filter those by session_id).

Bind an event to a sub-agent with one call — the spawn spec goes in the registration metadata; the fired event is appended to the task:

json
engine::register_trigger {
  "trigger_type": "harness::turn-completed",
  "config": { "session_id": "<child>" },
  "function_id": "harness::spawn",
  "metadata": { "task": "Summarize the completed run.", "once": true }
}

model defaults to the registering turn's model. A failed upstream turn does not fire the reaction unless continue_on_error: true. Reactive chains stop at depth 8. There is no fan-in join primitive — use the workflow worker to join parallel work.

An in-session registration that omits model also inherits its provider, when the spec pins none; raw engine-side registrations have no turn to inherit from and must pass one, and any supplied model must be a live id from router::models::list (validated at registration and again at fire time). Omit parent_session_id and the child nests under the registering session's root automatically; pin it only to choose a different REAL session (an invented id shows the children as disconnected roots). A trigger-fired spawn has no parent policy to inherit — it gets the harness's read-only default_functions baseline unless options.functions grants more (narrowing only, same as a direct harness::spawn call). Filter turn-completed only by session ids you know exist; registration returns a warning note when the filtered session doesn't. Self-edge drop and the depth cap are the ONLY loop breakers — still design filters so a reaction is not matched by its own subscription. A cycle routed through a state write (or any other hop that starts a fresh turn) re-enters at depth 0 and is NOT throttled: every lap around the cycle spawns another paid turn indefinitely. Design reaction graphs acyclically. This is the in-run agent's chaining path; the registerFunction recipe below is for workers.

How to bind
  1. Register a handler: registerFunction('myapp::on-turn-done', handler).
  2. Register the trigger:
typescript
iii.registerTrigger({
  type: 'harness::turn-completed',
  function_id: 'myapp::on-turn-done',
  config: { session_id: sessionId },
})

For the event payload shape, call get function info on the trigger type.

Hooks (policy siblings only)

The harness also registers five synchronous, in-path hook trigger types: harness::hook::pre-turn, harness::hook::pre-generate, harness::hook::post-generate, harness::hook::pre-trigger, and harness::hook::post-trigger. A bound hook runs in the turn's critical path and the harness acts on its return value (veto / hold / mutate) under a per-binding timeout_ms and on_error policy; pre-trigger / post-trigger bindings take a functions glob list to scope which calls they gate. These are for operator-trusted policy siblings (approval-gate binds pre-trigger); ordinary consumers do not bind hooks.

© iii-hq, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in harness/skills of iii-hq/workers.

  • SKILL.md
  • orchestration.md

Open the folder on GitHubat commit ebfe027

Compare with similar skills

Harness next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Harness compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Harness this skilliii-hq/workers113—~2.6kAutomated safety check: PassApache-2.0
Web Artifacts Builderanthropics/skills180k40 repos~769Automated safety check: PassApache-2.0
Vercel Composition Patternssupabase/supabase111k58 repos~726Automated safety check: PassMIT
React Doctormakeplane/plane61k12 repos~657Automated safety check: PassAGPL-3.0
React Router Developmentremix-run/react-router57k1 repos~1.5kAutomated safety check: PassMIT
React UI State PatternsChrisWiles/claude-code-showcase6.1k8 repos~1.6kAutomated safety check: PassNone

Similar skills

  • Web Artifacts Builder

    anthropics/skills

    Official

    Builds multi-component claude.ai HTML artifacts as a small React, TypeScript and Tailwind project, then bundles it into one shareable HTML file.

    180k GitHub starsUsed in 40 repos~769 tokens
    Frontend & DesignAuto-check passed
  • Official

    React composition patterns that scale. An agent skill from supabase/supabase.

    111k GitHub starsUsed in 58 repos~726 tokens
    DevelopmentAuto-check passed
  • React Doctor

    makeplane/plane

    Scans React code for lint, accessibility, bundle size and architecture issues, reports a health score and checks that changes do not lower it.

    61k GitHub starsUsed in 12 repos~657 tokens
    Frontend & DesignAuto-check passed
  • React Router Development

    remix-run/react-router

    Guides work on React Router apps by first identifying whether the app uses Framework, Data or Declarative mode, then loading the matching reference and the installed package docs.

    57k GitHub starsUsed in 1 repo~1.5k tokens
    Frontend & DesignAuto-check passed
  • React UI State Patterns

    ChrisWiles/claude-code-showcase

    Sets patterns for React interfaces: when to show loading spinners or skeletons, how to surface errors, how to disable buttons during async work and how to handle empty lists.

    6.1k GitHub starsUsed in 8 repos~1.6k tokens
    Frontend & DesignAuto-check passed
  • Tells the agent where new code belongs in an Electron multi-process project and which APIs each process may use, with rules for new bridges, services, agents and workers.

    33k GitHub starsUsed in 1 repo~1.8k tokens
    DevelopmentAuto-check passed

More from iii-hq/workers

All 19 skills in this repo
  • Cron

    iii-hq/workers

    Schedule any registered function on a 6- or 7-field cron expression with the standalone cron worker.

    113 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Email

    iii-hq/workers

    Send and read email from the iii engine — SMTP send, IMAP read, and real-time IDLE push as a subscribable trigger type.

    113 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • HTTP

    iii-hq/workers

    Expose registered functions as HTTP endpoints with the standalone http worker.

    113 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Kanban

    iii-hq/workers

    File-backed kanban board: create, read, move and comment on tickets by key or uuid, assign agent profiles, and wake on comments through the kanban:comment trigger instead of polling.

    113 GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Pubsub

    iii-hq/workers

    DEPRECATED (will be removed in an upcoming release; migration guide https://iii.dev/docs/upgrading/migrate-from-streams).

    113 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Release Sync

    iii-hq/workers

    Organize worker release tags into Linear release waves — one team document plus one release/<date label per same-day batch of worker releases, with shipped MOT issues labeled and linked.

    113 GitHub stars~1.1k tokensUpdated today
    Auto-check passed

Works with

Questions about Harness

What does Harness do?

The durable agent turn loop — kick off a turn with harness::send, render it from session-manager transcript events, react to harness::turn-completed, with deny-by-default tool dispatch and…. Harness is an agent skill from iii-hq/workers. The durable agent turn loop — kick off a turn with harness::send, render it from session-manager transcript events, react to harness::turn-completed, with deny-by-default tool dispatch and synchronous hook extension points for policy siblings.

How do I install Harness in Claude Code?

Run `npx skills add iii-hq/workers --skill harness -a claude-code`. Or copy the skill folder (harness/skills in iii-hq/workers) into .claude/skills/harness in your project. Claude Code loads it when a task matches its description.

How do I install Harness in Codex?

Run `npx skills add iii-hq/workers --skill harness -a codex`. Or copy the skill folder (harness/skills in iii-hq/workers) into .agents/skills/harness in your project. Codex loads it when a task matches its description.

Can I use Harness in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add iii-hq/workers --skill harness -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/harness, .gemini/skills/harness, .github/skills/harness and .opencode/skills/harness in your project.

What does Harness need to run?

SKILL.md names no scripts, command-line tools or credentials: Harness is instructions for the agent only.

Does Harness access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Harness safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Harness use?

Harness is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Harness use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Harness?

Skills that share tags, products or a category with Harness: Web Artifacts Builder (anthropics/skills, 180k stars), Vercel Composition Patterns (supabase/supabase, 111k stars), React Doctor (makeplane/plane, 61k stars) and React Router Development (remix-run/react-router, 57k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Harness?

iii-hq (a GitHub organization) maintains it in iii-hq/workers, which has 113 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 10, 2026.

Source: iii-hq/workers on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.