Agent skill

Harness Threat Model

by ruvnet in ruvnet/ruflo

Enterprise-review-grade threat model from harness threat-model {path}.

MITAuto-check: notesSecurity

Install Harness Threat Model

skills CLI
$ npx skills add ruvnet/ruflo --skill harness-threat-model -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ruvnet/ruflo harness-threat-model --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ruvnet/ruflo.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/ruflo-metaharness/skills/harness-threat-model .claude/skills/harness-threat-model && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
harness-threat-model
GitHub stars
74k
Token cost
~363 tokens
SKILL.md length
132 words
Files
1
Skills in repo
265
Repo updated
First seen
Licence
MIT

At a glance

Enterprise-review-grade threat model from harness threat-model {path}.

  • Works in 3 steps: Invoke the pinned harness binary… → Parse { worst, findings[] }. → fail-on : exit 1 when worst >= fail-on.…
  • Tasks that involve Threat modeling
  • SKILL.md covers Algorithm, Severity rank, When to use and Graceful degradation
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Harness Threat Model is an agent skill from ruvnet/ruflo. Enterprise-review-grade threat model from harness threat-model {path}. Categorizes MCP-surface threats; emits worst: 'clean'|'low'|'medium'|'high' + per-threat findings. Pure-read.

Its SKILL.md is about 360 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Threat modeling. It works with Model Context Protocol. The repository describes itself as: 🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory…. The licence is MIT.

When your agent uses it

  • Tasks that involve Threat modeling

Example prompts

  • “medium”
  • “/harness-threat-model”

Requirements

  • Pre-approved tools (allowed-tools): Bash

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Invoke the pinned harness binary (metaharness@~0.4.1, resolved from a
  2. Parse { worst, findings[] }.
  3. fail-on : exit 1 when worst >= fail-on. Default high.

What it can do on your machine

Read from SKILL.md and the folder at commit 6c04654. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Harness Threat Model loads about 363 tokens when it runs. Until then it costs about 51 tokens; SKILL.md has 132 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~51
When it runs · the whole SKILL.md, loaded when a task matches
~363

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ruvnet/ruflo at commit 6c04654, republished under its MIT licence (© ruvnet). 132 words, ~363 tokens.

Download SKILL.mdSave it as .claude/skills/harness-threat-model/SKILL.md (or your agent's skills folder).
name
harness-threat-model
description
Enterprise-review-grade threat model from `harness threat-model {path}`. Categorizes MCP-surface threats; emits `worst: 'clean'|'low'|'medium'|'high'` + per-threat findings. Pure-read.
allowed-tools
Bash
argument-hint
[--path .] [--fail-on clean|low|medium|high] [--format table|json]

The companion to harness-mcp-scan for enterprise security reviews. Where mcp-scan is a per-server static lint, threat-model produces a categorized report suitable for sharing with an InfoSec team.

Algorithm

Implementation: scripts/threat-model.mjs.

  1. Invoke the pinned harness binary (metaharness@~0.4.1, resolved from a local install or the one-time ~/.ruflo/metaharness-cache-<pin> cache — never @latest): harness threat-model <path> --json.
  2. Parse { worst, findings[] }.
  3. --fail-on <severity>: exit 1 when worst >= fail-on. Default high.

Severity rank

SeverityRank
clean0
low1
medium2
high3

When to use

  • Pre-launch review: include the JSON output in the release-readiness packet sent to security.
  • Periodic audit: schedule via the planned oia-audit background worker (ADR-150 Phase 2) to detect MCP-surface drift.

Graceful degradation

Same pattern as the other skills: when harness is absent, emit { degraded: true } and exit 0. ADR-150 architectural constraint.

© ruvnet, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/ruflo-metaharness/skills/harness-threat-model of ruvnet/ruflo.

Open the folder on GitHubat commit 6c04654

Compare with similar skills

Harness Threat Model next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Harness Threat Model compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Harness Threat Model this skillruvnet/ruflo74k—~363Automated safety check: NotesMIT
Forensifyalexgreensh/repo-forensics190—~2.5kAutomated safety check: NotesCustom licence
Vuln Hunterdariushoule/x64dbg-skills209—~3.9kAutomated safety check: NotesMIT
Security Analystantonbabenko/deliberation170—~1.1kAutomated safety check: PassMIT
MCP Gateway SecurityHack23/cia239—~2.4kAutomated safety check: PassApache-2.0
Threat Modelruvnet/metaharness696—~637Automated safety check: NotesMIT

Similar skills

  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    190 GitHub stars~2.5k tokensUpdated 13 days ago
    SecurityAuto-check: notes
  • Vuln Hunter

    dariushoule/x64dbg-skills

    Hunt for vulnerabilities in a running debuggee by analyzing imports/exports, triaging attack surface, and iteratively testing for bugs with PoC generation.

    209 GitHub stars~3.9k tokensUpdated 7 mo ago
    SecurityAuto-check: notes
  • Security Analyst

    antonbabenko/deliberation

    Threat-model and find vulnerabilities, with practical remediation.

    170 GitHub stars~1.1k tokensUpdated yesterday
    SecurityAuto-check passed
  • MCP gateway security patterns, token management, request validation, and audit logging for MCP communications

    239 GitHub stars~2.4k tokensUpdated today
    SecurityAuto-check passed
  • Threat Model

    ruvnet/metaharness

    MCP threat-model artifact for a scaffolded harness. An agent skill from ruvnet/metaharness.

    696 GitHub stars~637 tokensUpdated today
    SecurityAuto-check: notes
  • Review Maple Security

    MaplePrivacyLabs/Maple

    Review Maple security across authentication, account isolation, local persistence, Tauri IPC and capabilities, OAuth and deep links, the Local OpenAI Proxy, Agent Mode tools and permissions, MCP…

    102 GitHub stars~7.1k tokensUpdated today
    SecurityAuto-check passed

More from ruvnet/ruflo

All 265 skills in this repo
  • Stores, searches, and retrieves successful patterns with HNSW-indexed semantic search so agents can reuse past solutions instead of relearning them.

    74k GitHub starsUsed in 2 repos~830 tokens
    Auto-check passed
  • Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

    74k GitHub starsUsed in 2 repos~823 tokens
    Auto-check passed
  • Applies the SPARC method (specification, pseudocode, architecture, refinement, completion) with 17 specialized modes and multi-agent orchestration, from research to deployment.

    74k GitHub starsUsed in 2 repos~829 tokens
    Auto-check passed
  • Coordinates a hierarchical swarm of specialized agents through the claude-flow CLI for work that spans several files or modules at once.

    74k GitHub starsUsed in 2 repos~779 tokens
    Auto-check passed
  • Sets up and drives Ruflo, an npm-installed orchestration layer for multi-agent swarms, persistent memory, routing, hooks and its MCP tool catalog.

    74k GitHub starsUsed in 1 repo~975 tokens
    Auto-check passed
  • Agent Coordination

    ruvnet/ruflo

    Reference for spawning, listing, monitoring and stopping agents with claude-flow commands, with agent type families, routing codes and coordination tips.

    74k GitHub starsUsed in 2 repos~519 tokens
    Auto-check passed

Categories

Questions about Harness Threat Model

What does Harness Threat Model do?

Enterprise-review-grade threat model from harness threat-model {path}. Harness Threat Model is an agent skill from ruvnet/ruflo. Enterprise-review-grade threat model from harness threat-model {path}.

When should I use Harness Threat Model?

Harness Threat Model fits situations like: tasks that involve Threat modeling.

How do I install Harness Threat Model in Claude Code?

Run `npx skills add ruvnet/ruflo --skill harness-threat-model -a claude-code`. Or copy the skill folder (plugins/ruflo-metaharness/skills/harness-threat-model in ruvnet/ruflo) into .claude/skills/harness-threat-model in your project. Claude Code loads it when a task matches its description.

How do I install Harness Threat Model in Codex?

Run `npx skills add ruvnet/ruflo --skill harness-threat-model -a codex`. Or copy the skill folder (plugins/ruflo-metaharness/skills/harness-threat-model in ruvnet/ruflo) into .agents/skills/harness-threat-model in your project. Codex loads it when a task matches its description.

Can I use Harness Threat Model in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ruvnet/ruflo --skill harness-threat-model -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/harness-threat-model, .gemini/skills/harness-threat-model, .github/skills/harness-threat-model and .opencode/skills/harness-threat-model in your project.

What does Harness Threat Model need to run?

SKILL.md names no scripts, command-line tools or credentials: Harness Threat Model is instructions for the agent only. Its frontmatter pre-approves these tools: Bash.

Does Harness Threat Model access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Harness Threat Model safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Harness Threat Model use?

Harness Threat Model is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Harness Threat Model use?

About 363 tokens (SKILL.md is roughly 1.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Harness Threat Model?

Skills that share tags, products or a category with Harness Threat Model: Forensify (alexgreensh/repo-forensics, 190 stars), Vuln Hunter (dariushoule/x64dbg-skills, 209 stars), Security Analyst (antonbabenko/deliberation, 170 stars) and MCP Gateway Security (Hack23/cia, 239 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Harness Threat Model?

ruvnet (a GitHub user) maintains it in ruvnet/ruflo, which has 74,222 GitHub stars. The repository holds 265 skills in this directory. The repository was last updated on October 10, 2026.

Source: ruvnet/ruflo on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.