Agent skill

Harness Secrets

by ruvnet in ruvnet/metaharness

GCP Secret Manager integration: validate setup, fetch values, or confirm an NPMTOKEN is non-revoked via npm whoami.

MITAuto-check passedAgent Workflows

Install Harness Secrets

skills CLI
$ npx skills add ruvnet/metaharness --skill harness-secrets -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ruvnet/metaharness harness-secrets --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ruvnet/metaharness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude-plugin/skills/harness-secrets .claude/skills/harness-secrets && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
harness-secrets
GitHub stars
690
Token cost
~345 tokens
SKILL.md length
93 words
Files
1
Skills in repo
14
Repo updated
First seen
Licence
MIT

At a glance

GCP Secret Manager integration: validate setup, fetch values, or confirm an NPMTOKEN is non-revoked via npm whoami.

  • Agent Workflows work in your project
  • SKILL.md covers Modes, Equivalent CLI and Why this exists
  • Calls npm; needs NPM_TOKEN and GH_TOKEN

What it does

Harness Secrets is an agent skill from ruvnet/metaharness. GCP Secret Manager integration: validate setup, fetch values, or confirm an NPMTOKEN is non-revoked via npm whoami. Used for publish-time token rotation without long-lived keys in CI.

Its SKILL.md is about 350 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Agent Workflows. It works with Google Cloud, npm and Model Context Protocol. The repository describes itself as: 🛠️ The meta-harness for AI agents — scaffold your own focused, branded agent harness with its own npx CLI, MCP server, memory, learning loop, and witness-signed releases. Works… The licence is MIT.

When your agent uses it

  • Agent Workflows work in your project

Example prompts

  • “/harness-secrets”

Requirements

  • A credential in NPM_TOKEN

What it can do on your machine

Read from SKILL.md and the folder at commit ea287d6. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • NPM_TOKEN
    • GH_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Harness Secrets loads about 345 tokens when it runs. Until then it costs about 51 tokens; SKILL.md has 93 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~51
When it runs · the whole SKILL.md, loaded when a task matches
~345

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ruvnet/metaharness at commit ea287d6, republished under its MIT licence (© ruvnet). 93 words, ~345 tokens.

Download SKILL.mdSave it as .claude/skills/harness-secrets/SKILL.md (or your agent's skills folder).
name
harness-secrets
description
GCP Secret Manager integration: validate setup, fetch values, or confirm an NPM_TOKEN is non-revoked via `npm whoami`. Used for publish-time token rotation without long-lived keys in CI.

harness-secrets

Codex skill for GCP Secret Manager — check / fetch / validate-token.

Modes

check

Validates the full GCP setup (gcloud on PATH, active project, auth principal, secret exists, WIF pool present). Use this when bootstrapping a new GCP project for publish.

/harness-secrets mode=check
/harness-secrets mode=check secret=NPM_TOKEN_DEV
/harness-secrets mode=check project=my-gcp-project secret=NPM_TOKEN
fetch

Fetches a secret value to stdout. Use in pipelines:

/harness-secrets mode=fetch secret=NPM_TOKEN
/harness-secrets mode=fetch secret=GH_TOKEN version=3
validate-token

Fetches NPM_TOKEN and runs npm whoami against the registry. No publish — just confirms the token isn't revoked. Use this BEFORE you tag a release.

/harness-secrets mode=validate-token
/harness-secrets mode=validate-token secret=NPM_TOKEN_STAGING

Equivalent CLI

bash
harness secrets check --secret=NPM_TOKEN
harness secrets fetch NPM_TOKEN --version=3
harness secrets validate-token

Why this exists

So you can refresh + verify the publish-time GCP secret WITHOUT triggering a real publish.

© ruvnet, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude-plugin/skills/harness-secrets of ruvnet/metaharness.

Open the folder on GitHubat commit ea287d6

Compare with similar skills

Harness Secrets next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Harness Secrets compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Harness Secrets this skillruvnet/metaharness690—~345Automated safety check: PassMIT
MCP Server BuildershareAI-lab/learn-claude-code78k5 repos~1.2kAutomated safety check: PassMIT
Orca Run Replayiflytek/skillhub5.2k4 repos~3kAutomated safety check: PassApache-2.0
Yahoo Finance2gadicc/yahoo-finance2801—~1.8kAutomated safety check: PassMIT
Workflow Schema Tuningbreaking-brake/cc-wf-studio5.4k—~1.3kAutomated safety check: PassCustom licence
Paseo Plugin Buildergetpaseo/paseo20k—~9.4kAutomated safety check: PassCustom licence

Similar skills

  • MCP Server Builder

    shareAI-lab/learn-claude-code

    Walks through building MCP servers in Python or TypeScript that expose tools, resources and prompts to Claude, with templates, registration and testing.

    78k GitHub starsUsed in 5 repos~1.2k tokens
    Agent WorkflowsAuto-check passed
  • Orca Run Replay

    iflytek/skillhub

    Answers questions about a past agent run from its recording, using causal graphs and replay, instead of reconstructing events from memory.

    5.2k GitHub starsUsed in 4 repos~3k tokens
    Agent WorkflowsAuto-check passed
  • Yahoo Finance2

    gadicc/yahoo-finance2

    A skill your agent uses when building with the yahoo-finance2 TypeScript/Deno/npm library, using its Yahoo Finance data modules, CLI, or MCP server, or contributing to the yahoo-finance2 repository…

    801 GitHub stars~1.8k tokensUpdated 4 days ago
    Agent WorkflowsAuto-check passed
  • Workflow Schema Tuning

    breaking-brake/cc-wf-studio

    Guides edits to cc-wf-studio's workflow schema so AI agents generate better workflows, treating schema text as prompt engineering rather than validation.

    5.4k GitHub stars~1.3k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • Paseo Plugin Builder

    getpaseo/paseo

    Builds, installs and troubleshoots trusted local Paseo plugins, from lifecycle hooks and slash commands to screens, themes and timeline renderers.

    20k GitHub stars~9.4k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Context Mode Doctor

    mksglu/context-mode

    Run context-mode diagnostics. Checks runtimes, hooks, FTS5, plugin registration, npm and marketplace versions. Trigger: /context-mode:ctx-doctor

    26k GitHub stars~262 tokensUpdated yesterday
    Agent WorkflowsAuto-check passed

More from ruvnet/metaharness

All 14 skills in this repo
  • Create Harness

    ruvnet/metaharness

    Scaffold your own focused AI agent harness — pick host (Claude Code, Codex, pi.dev, Hermes), template, agents, skills, and ship a npm-publishable harness with its own npx CLI.

    690 GitHub stars~777 tokensUpdated yesterday
    Auto-check passed
  • Compare Harnesses

    ruvnet/metaharness

    Diff two scaffolded harnesses (ADR-031). An agent skill from ruvnet/metaharness.

    690 GitHub stars~1k tokensUpdated yesterday
    Auto-check passed
  • Diag Harness

    ruvnet/metaharness

    Kernel-version skew check (ADR-027). An agent skill from ruvnet/metaharness.

    690 GitHub stars~835 tokensUpdated yesterday
    Auto-check passed
  • Example Harness

    ruvnet/metaharness

    Scaffold a ready-made AI agent harness in one command from the 19 published @metaharness/ example packages — 9 host integrations (Claude Code, Codex, Hermes, pi.dev, OpenClaw, RVM, Copilot…

    690 GitHub stars~735 tokensUpdated yesterday
    Auto-check passed
  • Oia Manifest

    ruvnet/metaharness

    Emit .harness/oia-manifest.json declaring layer alignment with the OIA v0.1 9-layer reference architecture.

    690 GitHub stars~910 tokensUpdated yesterday
    Auto-check passed
  • Repo Genome

    ruvnet/metaharness

    7-section readiness scorecard for a LOCAL repo. An agent skill from ruvnet/metaharness.

    690 GitHub stars~772 tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Harness Secrets

What does Harness Secrets do?

GCP Secret Manager integration: validate setup, fetch values, or confirm an NPMTOKEN is non-revoked via npm whoami. Harness Secrets is an agent skill from ruvnet/metaharness. GCP Secret Manager integration: validate setup, fetch values, or confirm an NPMTOKEN is non-revoked via npm whoami.

When should I use Harness Secrets?

Harness Secrets fits situations like: agent Workflows work in your project.

How do I install Harness Secrets in Claude Code?

Run `npx skills add ruvnet/metaharness --skill harness-secrets -a claude-code`. Or copy the skill folder (.claude-plugin/skills/harness-secrets in ruvnet/metaharness) into .claude/skills/harness-secrets in your project. Claude Code loads it when a task matches its description.

How do I install Harness Secrets in Codex?

Run `npx skills add ruvnet/metaharness --skill harness-secrets -a codex`. Or copy the skill folder (.claude-plugin/skills/harness-secrets in ruvnet/metaharness) into .agents/skills/harness-secrets in your project. Codex loads it when a task matches its description.

Can I use Harness Secrets in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ruvnet/metaharness --skill harness-secrets -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/harness-secrets, .gemini/skills/harness-secrets, .github/skills/harness-secrets and .opencode/skills/harness-secrets in your project.

What does Harness Secrets need to run?

Going by SKILL.md and its folder, Harness Secrets needs the command-line tools its instructions call (npm) and credentials named NPM_TOKEN and GH_TOKEN. Our summary lists: A credential in NPM_TOKEN.

Does Harness Secrets access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Harness Secrets safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Harness Secrets use?

Harness Secrets is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Harness Secrets use?

About 345 tokens (SKILL.md is roughly 1.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Harness Secrets?

Skills that share tags, products or a category with Harness Secrets: MCP Server Builder (shareAI-lab/learn-claude-code, 78k stars), Orca Run Replay (iflytek/skillhub, 5.2k stars), Yahoo Finance2 (gadicc/yahoo-finance2, 801 stars) and Workflow Schema Tuning (breaking-brake/cc-wf-studio, 5.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Harness Secrets?

ruvnet (a GitHub user) maintains it in ruvnet/metaharness, which has 690 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on October 7, 2026.

Source: ruvnet/metaharness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.