Agent skill

Validate Harness

by ruvnet in ruvnet/metaharness

Release-readiness umbrella check for a scaffolded harness — runs doctor, witness verify, hardcoded-path scan, MCP server config, and GCP Secret Manager validation in one shot.

MITAuto-check passedProduct & Project Management

Install Validate Harness

skills CLI
$ npx skills add ruvnet/metaharness --skill validate-harness -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ruvnet/metaharness validate-harness --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ruvnet/metaharness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude-plugin/skills/validate-harness .claude/skills/validate-harness && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
validate-harness
GitHub stars
690
Token cost
~372 tokens
SKILL.md length
126 words
Files
1
Skills in repo
14
Repo updated
First seen
Licence
MIT

At a glance

Release-readiness umbrella check for a scaffolded harness — runs doctor, witness verify, hardcoded-path scan, MCP server config, and GCP Secret Manager validation in one shot.

  • Tasks that involve Project scaffolding
  • SKILL.md covers What it checks, Usage from Codex, Equivalent CLI and Why this exists
  • Calls gcloud and node; needs NPM_TOKEN
  • Tasks that involve Feature launches and release readiness

What it does

Validate Harness is an agent skill from ruvnet/metaharness. Release-readiness umbrella check for a scaffolded harness — runs doctor, witness verify, hardcoded-path scan, MCP server config, and GCP Secret Manager validation in one shot. Exits non-zero if any sub-check fails.

Its SKILL.md is about 370 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Product & Project Management, covering Project scaffolding, Feature launches and release readiness and MCP servers. It works with Model Context Protocol and Google Cloud. The repository describes itself as: 🛠️ The meta-harness for AI agents — scaffold your own focused, branded agent harness with its own npx CLI, MCP server, memory, learning loop, and witness-signed releases. Works… The licence is MIT.

When your agent uses it

  • Tasks that involve Project scaffolding
  • Tasks that involve Feature launches and release readiness
  • Tasks that involve MCP servers

Example prompts

  • “/validate-harness”

Requirements

  • A credential in NPM_TOKEN

What it can do on your machine

Read from SKILL.md and the folder at commit ea287d6. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gcloud
    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gcloud, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • NPM_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Validate Harness loads about 372 tokens when it runs. Until then it costs about 58 tokens; SKILL.md has 126 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~58
When it runs · the whole SKILL.md, loaded when a task matches
~372

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ruvnet/metaharness at commit ea287d6, republished under its MIT licence (© ruvnet). 126 words, ~372 tokens.

Download SKILL.mdSave it as .claude/skills/validate-harness/SKILL.md (or your agent's skills folder).
name
validate-harness
description
Release-readiness umbrella check for a scaffolded harness — runs doctor, witness verify, hardcoded-path scan, MCP server config, and GCP Secret Manager validation in one shot. Exits non-zero if any sub-check fails.

validate-harness

Codex skill that runs the 5 release-readiness gates from harness validate.

What it checks

#CheckWhat it does
1doctorFile shape + manifest sha256 + at-least-one host artifact
2verifyWitness manifest signature (Ed25519) — skipped if no witness yet
3path-guardScans your TS/JS/Rust files for hardcoded /tmp/, C:\, /Users/, /home/ — the original Windows /tmp bug regression class
4mcp.mcp/servers.json entries have name + command
5secretsgcloud auth list + project + NPM_TOKEN exist in GCP Secret Manager

Each check reports PASS / FAIL / WARN with a one-line detail. Exits 1 if any FAIL.

Usage from Codex

/validate-harness
/validate-harness path=./my-harness
/validate-harness path=./my-harness skip_gcp=true
/validate-harness secret=NPM_TOKEN_DEV

Equivalent CLI

bash
harness validate ./my-harness --skip-gcp --secret=NPM_TOKEN_DEV

Why this exists

Before iter 20, you needed to remember to run harness doctor, harness verify, harness secrets check, and node scripts/path-guard.mjs separately. This is the single release-readiness gate.

© ruvnet, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude-plugin/skills/validate-harness of ruvnet/metaharness.

Open the folder on GitHubat commit ea287d6

Compare with similar skills

Validate Harness next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Validate Harness compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Validate Harness this skillruvnet/metaharness690—~372Automated safety check: PassMIT
Azsdk Common SDK ReleaseAzure/azure-sdk-for-android121—~478Automated safety check: PassMIT
Chatgpt AppsHaohao-end/openagent8071 repos~4.9kAutomated safety check: PassApache-2.0
MCP Scaffoldtimothywarner-org/claude-code224—~940Automated safety check: PassMIT
Jira Natural Language Interfacejjmartres/opencode1333 repos~1.7kAutomated safety check: PassMIT
AI Bomcdxgen/cdxgen1.1k—~2.5kAutomated safety check: PassApache-2.0

Similar skills

  • Azsdk Common SDK Release

    Azure/azure-sdk-for-android

    Official

    Check release readiness and trigger the release pipeline for Azure SDK packages.

    121 GitHub stars~478 tokensUpdated 4 mo ago
    Product & Project ManagementAuto-check passed
  • Chatgpt Apps

    Haohao-end/openagent

    Build, scaffold, refactor, and troubleshoot ChatGPT Apps SDK applications that combine an MCP server and widget UI.

    807 GitHub starsUsed in 1 repo~4.9k tokens
    Agent WorkflowsAuto-check passed
  • MCP Scaffold

    timothywarner-org/claude-code

    Scaffold production-ready Python MCP servers using FastMCP. An agent skill from timothywarner-org/claude-code.

    224 GitHub stars~940 tokensUpdated 2 mo ago
    Agent WorkflowsAuto-check passed
  • Lets an agent view, create, update and transition Jira issues in natural language, automatically choosing between the jira CLI and Atlassian MCP tools.

    133 GitHub starsUsed in 3 repos~1.7k tokens
    Product & Project ManagementAuto-check passed
  • AI Bom

    cdxgen/cdxgen

    Generates AI-BOM, MCP inventory, AI skill inventory, and AI authorship provenance documents with cdxgen, cataloging models, inference services, Hugging Face purls, MCP servers and their…

    1.1k GitHub stars~2.5k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Lunora

    anolilab/lunora

    Routes general Lunora requests to the right Lunora skill and gives the shared mental model (codegen loop, generated api/internal references, review commands, add-on capabilities, the @lunora/mcp…

    283 GitHub stars~2.6k tokensUpdated today
    Backend & APIsAuto-check passed

More from ruvnet/metaharness

All 14 skills in this repo
  • Create Harness

    ruvnet/metaharness

    Scaffold your own focused AI agent harness — pick host (Claude Code, Codex, pi.dev, Hermes), template, agents, skills, and ship a npm-publishable harness with its own npx CLI.

    690 GitHub stars~777 tokensUpdated today
    Auto-check passed
  • Compare Harnesses

    ruvnet/metaharness

    Diff two scaffolded harnesses (ADR-031). An agent skill from ruvnet/metaharness.

    690 GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Diag Harness

    ruvnet/metaharness

    Kernel-version skew check (ADR-027). An agent skill from ruvnet/metaharness.

    690 GitHub stars~835 tokensUpdated today
    Auto-check passed
  • Example Harness

    ruvnet/metaharness

    Scaffold a ready-made AI agent harness in one command from the 19 published @metaharness/ example packages — 9 host integrations (Claude Code, Codex, Hermes, pi.dev, OpenClaw, RVM, Copilot…

    690 GitHub stars~735 tokensUpdated today
    Auto-check passed
  • Oia Manifest

    ruvnet/metaharness

    Emit .harness/oia-manifest.json declaring layer alignment with the OIA v0.1 9-layer reference architecture.

    690 GitHub stars~910 tokensUpdated today
    Auto-check passed
  • Repo Genome

    ruvnet/metaharness

    7-section readiness scorecard for a LOCAL repo. An agent skill from ruvnet/metaharness.

    690 GitHub stars~772 tokensUpdated today
    Auto-check passed

Questions about Validate Harness

What does Validate Harness do?

Release-readiness umbrella check for a scaffolded harness — runs doctor, witness verify, hardcoded-path scan, MCP server config, and GCP Secret Manager validation in one shot. Validate Harness is an agent skill from ruvnet/metaharness. Release-readiness umbrella check for a scaffolded harness — runs doctor, witness verify, hardcoded-path scan, MCP server config, and GCP Secret Manager validation in one shot.

When should I use Validate Harness?

Validate Harness fits situations like: tasks that involve Project scaffolding; tasks that involve Feature launches and release readiness; tasks that involve MCP servers.

How do I install Validate Harness in Claude Code?

Run `npx skills add ruvnet/metaharness --skill validate-harness -a claude-code`. Or copy the skill folder (.claude-plugin/skills/validate-harness in ruvnet/metaharness) into .claude/skills/validate-harness in your project. Claude Code loads it when a task matches its description.

How do I install Validate Harness in Codex?

Run `npx skills add ruvnet/metaharness --skill validate-harness -a codex`. Or copy the skill folder (.claude-plugin/skills/validate-harness in ruvnet/metaharness) into .agents/skills/validate-harness in your project. Codex loads it when a task matches its description.

Can I use Validate Harness in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ruvnet/metaharness --skill validate-harness -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/validate-harness, .gemini/skills/validate-harness, .github/skills/validate-harness and .opencode/skills/validate-harness in your project.

What does Validate Harness need to run?

Going by SKILL.md and its folder, Validate Harness needs the command-line tools its instructions call (gcloud and node) and credentials named NPM_TOKEN. Our summary lists: A credential in NPM_TOKEN.

Does Validate Harness access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Validate Harness safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Validate Harness use?

Validate Harness is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Validate Harness use?

About 372 tokens (SKILL.md is roughly 1.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Validate Harness?

Skills that share tags, products or a category with Validate Harness: Azsdk Common SDK Release (Azure/azure-sdk-for-android, 121 stars), Chatgpt Apps (Haohao-end/openagent, 807 stars), MCP Scaffold (timothywarner-org/claude-code, 224 stars) and Jira Natural Language Interface (jjmartres/opencode, 133 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Validate Harness?

ruvnet (a GitHub user) maintains it in ruvnet/metaharness, which has 690 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on October 7, 2026.

Source: ruvnet/metaharness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.