vphone600 Kernel Symbol Analysis
Lakr233/vphone-cli
Looks up symbols and addresses in vphone600 release and research kernel datasets, and cross-references XNU source, with findings that separate fact from inference.
A skill your agent uses whenever the user asks the running agent to gain a new capability — phrasings like "build a tool", "add a hook", "give yourself X", "let me <do thing through you", or…
$ npx skills add wedow/harness --skill extend-harness -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install wedow/harness extend-harness --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/wedow/harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/core/skills/extend-harness .claude/skills/extend-harness && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "extend-harness" agent skill from https://github.com/wedow/harness/tree/master/plugins/core/skills/extend-harness into .claude/skills/extend-harness/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "extend-harness", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/wedow/harness/tree/master/plugins/core/skills/extend-harnessType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add wedow/harness --skill extend-harness -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install wedow/harness extend-harness --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/wedow/harness.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/core/skills/extend-harness .agents/skills/extend-harness && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "extend-harness" agent skill from https://github.com/wedow/harness/tree/master/plugins/core/skills/extend-harness into .agents/skills/extend-harness/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "extend-harness", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add wedow/harness --skill extend-harness -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install wedow/harness extend-harness --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/wedow/harness.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/core/skills/extend-harness .cursor/skills/extend-harness && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "extend-harness" agent skill from https://github.com/wedow/harness/tree/master/plugins/core/skills/extend-harness into .cursor/skills/extend-harness/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "extend-harness", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/wedow/harness.git --path plugins/core/skills/extend-harness--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add wedow/harness --skill extend-harness -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install wedow/harness extend-harness --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/wedow/harness.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/core/skills/extend-harness .gemini/skills/extend-harness && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "extend-harness" agent skill from https://github.com/wedow/harness/tree/master/plugins/core/skills/extend-harness into .gemini/skills/extend-harness/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "extend-harness", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install wedow/harness extend-harnessInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add wedow/harness --skill extend-harness -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/wedow/harness.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/core/skills/extend-harness .github/skills/extend-harness && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "extend-harness" agent skill from https://github.com/wedow/harness/tree/master/plugins/core/skills/extend-harness into .github/skills/extend-harness/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "extend-harness", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add wedow/harness --skill extend-harness -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install wedow/harness extend-harness --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/wedow/harness.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/core/skills/extend-harness .opencode/skills/extend-harness && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "extend-harness" agent skill from https://github.com/wedow/harness/tree/master/plugins/core/skills/extend-harness into .opencode/skills/extend-harness/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "extend-harness", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
extend-harnessA skill your agent uses whenever the user asks the running agent to gain a new capability — phrasings like "build a tool", "add a hook", "give yourself X", "let me <do thing through you", or…
Extend Harness is an agent skill from wedow/harness. Use whenever the user asks the running agent to gain a new capability — phrasings like "build a tool", "add a hook", "give yourself X", "let me <do thing through you", or anything that extends the agent itself at runtime. Defines the plugin protocols, where to install them (.harness/ scopes), and the required test-through-tool-call iteration pattern. CRITICAL: "tool" here means a plugin the agent invokes via tool-calls — install it to a .harness/ directory; do NOT write a standalone CLI script in the working…
Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Reverse engineering and malware. The repository describes itself as: Minimal agent loop in bash. Pure state follower core with plugin-based tools, hooks, providers, and commands. Dependencies: bash 4+, jq, curl. The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 5f5d968. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
jqcurlFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
agents.mdFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Extend Harness loads about 2.4k tokens when it runs. Until then it costs about 175 tokens; SKILL.md has 923 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from wedow/harness at commit 5f5d968, republished under its MIT licence (© wedow). 923 words, ~2,431 tokens.
.claude/skills/extend-harness/SKILL.md (or your agent's skills folder).Harness is a state follower; everything else is plugins discovered at runtime from .harness/ directories. To extend the running agent — yourself — drop an executable into the right place. The next loop iteration picks it up; no restart needed (_refresh_sources runs every turn).
Discovery walks from CWD up to /, collecting every .harness/ directory. For same-named files, most-local wins. Pick scope based on lifetime and audience:
| Scope | Location | Use when |
|---|---|---|
| User-global | ~/.harness/ | Available everywhere; personal preferences, secrets |
| Project | <repo>/.harness/ | Committed with the repo, scoped to that project |
| Subdir | <dir>/.harness/ | Narrower scope inside a monorepo |
Inside any .harness/:
commands/ # CLI subcommands (hs <name>)
tools/ # tools the model can call
hooks.d/<stage>/ # pipeline hooks; sorted by NN- prefix
providers/ # LLM API adapters (binary or .conf variant)
prompts/*.md # appended to the system prompt
skills/<name>/ # on-demand instruction packs (SKILL.md)
plugins/<name>/ # plugin packs with the same layoutAGENTS.md follows the agents.md standard — placed at the parent of the .harness/ directory, not inside it.
A tool is an executable responding to three flags. Drop it at .harness/tools/<name> and chmod +x.
#!/usr/bin/env bash
set -euo pipefail
case "${1:-}" in
--schema) cat <<'JSON'
{"name":"web_get","description":"GET a URL and return body",
"input_schema":{"type":"object",
"properties":{"url":{"type":"string"}},
"required":["url"]}}
JSON
;;
--describe) echo "GET a URL" ;;
--exec)
url="$(jq -r '.url' < /dev/stdin)"
curl -fsS "$url"
;;
esacHARNESS_LOG. Non-zero exit marks the result as error: true.HARNESS_CWD (the session's original working directory).../../../../examples/tools/web_fetch for a Python example.Verify: hs tools lists what's discovered.
Each stage dispatches its hooks as a chain — each hook reads the previous one's stdout and writes JSON. The numeric NN- prefix sets order. Local same-basename overrides global, which lets you replace a bundled hook by name.
start → assemble → send → receive → done
↑ │
│ tool_exec → tool_done
│ │
└─────────────────┘The transition is not hardcoded — each hook may emit next_state and the loop follows it. Empty next_state ends the loop. output (string) is what's printed when the loop exits.
| Stage | Stdin | Default next | Use for |
|---|---|---|---|
sources | {} | (n/a) | Discover/filter plugin source dirs |
resolve | {provider,model} | (n/a) | Pick provider/model before the loop |
start | {} | assemble | Session init (e.g. set HARNESS_CWD) |
assemble | {} | send | Build payload (messages, tools, system) |
send | payload | receive | Call provider |
receive | API response | done | Save assistant msg, extract tool calls |
tool_exec | {tool_calls:[…]} | tool_done | Execute one tool call |
tool_done | tool result | tool_exec / assemble | Save result, route |
error | error context | (empty=stop) | Recover or report |
done | final context | (empty=stop) | Cleanup, terminal |
Pipeline rules:
NN- prefix).error.cat stdin to stdout after side effects, leaving the pipeline payload intact.{"next_state": "..."} (usually the last hook in the stage).Example — confirm bash before execution (gate hook on tool_exec):
#!/usr/bin/env bash
# .harness/hooks.d/tool_exec/05-confirm
set -euo pipefail
tc="$(cat)"
[[ "$(echo "$tc" | jq -r '.name')" == "bash" ]] || { echo "$tc"; exit 0; }
cmd="$(echo "$tc" | jq -r '.input.command')"
read -p "run: $cmd ? [y/N] " r </dev/tty
[[ "$r" =~ ^[Yy] ]] || exit 1
echo "$tc"Example — log token usage after each response (observer hook on receive):
#!/usr/bin/env bash
# .harness/hooks.d/receive/20-cost
set -euo pipefail
r="$(cat)"
in="$(echo "$r" | jq -r '.usage.input_tokens // 0')"
out="$(echo "$r" | jq -r '.usage.output_tokens // 0')"
echo "$(date -Iseconds) in=$in out=$out" >> "${HARNESS_SESSION}/cost.log"
echo "$r" # pass throughVerify: hs hooks <stage> lists what's discovered.
A skill is a directory under .harness/skills/<name>/ containing SKILL.md with YAML frontmatter (name, description). The 35-skills assemble hook injects only the catalog (name + description) into the system prompt — the model loads the full body via the skill tool when relevant. Optional sibling dirs (references/, scripts/, assets/) are listed so the model knows what auxiliary files exist.
.harness/skills/my-workflow/
SKILL.md # frontmatter + body
references/details.md # listed in <skill-resources>
scripts/setup.sh # listed in <skill-resources>Use a skill when instructions would bloat the system prompt but only matter for specific tasks. The description field is what triggers the model — make it concrete about when to load it.
A provider is an executable in providers/<name> reading payload JSON on stdin and writing the raw API response. Optional flags: --describe, --ready (exit 0 if creds set; used for auto-select), --defaults (model=… lines), --env, --stream.
A directory whose basename matches a binary in its providers/ (e.g. plugins/openai/providers/openai) is treated as a provider plugin — its hooks/tools/prompts only participate when that provider is active.
For OpenAI-compatible or Anthropic-compatible services, write a <name>.conf instead of a full binary:
protocol=openai
description=My Endpoint
model=foo-1
url=https://api.example.com/v1/chat/completions
auth_env=MY_API_KEYDrop in any providers/ dir; hs auth set <name> stores credentials under that name.
AGENTS.md files (at each .harness/ parent) are concatenated into the system prompt, global → local. For composable fragments inside .harness/, use prompts/*.md (sorted by filename, all loaded). Local fragments come last so they can refine global ones.
~/.harness/ for personal, <repo>/.harness/ for shared).write_file, not heredoc-via-bash, so the file is clean and easy to edit later.chmod +x — non-executable files are silently ignored. This is the most common omission.read_file or bash. Listing it with hs tools only proves discovery, not that the protocol implementation is correct; you must actually invoke it. For hooks, trigger the relevant stage (e.g. emit a tool call to exercise tool_exec). For commands, run hs <name> from bash. Never test a tool by shelling out (./tool --exec <<< '{...}') or by exiting back to the user with "ready to use" — both bypass the JSON dispatcher and silently skip protocol bugs (bad schema, wrong stdout shape, schema/exec mismatch, forgotten chmod +x).edit_file/write_file, and call again. Keep iterating until a real tool call returns the expected result. The task is not done until you have personally invoked the new extension through the loop and seen the right result — do not return control to the user with the extension untested.../../../../docs/PROTOCOLS.md../../../../examples/ — tools, gate hooks, observer hooks../../../../AGENTS.md and ../../../../README.md../../../../plugins/ — plugins/core/hooks.d/ for provider-agnostic hooks, plugins/anthropic/ and plugins/openai/ for full provider plugins, plugins/skills/ for the skill discovery hook itself.stream JSONL events) and canonical message format: see docs/PROTOCOLS.md© wedow, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in plugins/core/skills/extend-harness of wedow/harness.
Open the folder on GitHubat commit 5f5d968
Extend Harness next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Extend Harness this skillwedow/harness | 168 | — | ~2.4k | Automated safety check: Pass | MIT | |
| vphone600 Kernel Symbol AnalysisLakr233/vphone-cli | 15k | — | ~530 | Automated safety check: Pass | MIT | |
| Webhome Extension Builderwebhtv/webhtv | 1.7k | — | ~2.8k | Automated safety check: Pass | GPL-3.0 | |
| Reverse Flowlingbol088-spec/reverse-flow-skill | 940 | — | ~2.4k | Automated safety check: Pass | MIT | |
| Website Rebuildboyang-hu/website-rebuild-skill | 1.4k | — | ~6.1k | Automated safety check: Pass | MIT | |
| Client Request Signature Reversalawarexone/Agentic-Bug-Hunter | 5.3k | — | ~4.7k | Automated safety check: Pass | MIT |
Lakr233/vphone-cli
Looks up symbols and addresses in vphone600 release and research kernel datasets, and cross-references XNU source, with findings that separate fact from inference.
webhtv/webhtv
Build, review, debug, reverse-engineer, and package WebHome injected extension scripts for FongMi/WebHome App WebView pages.
lingbol088-spec/reverse-flow-skill
Guided reverse engineering workflow for binaries, firmware, mobile apps, scripts, document samples, protocol captures, and unknown artifacts.
boyang-hu/website-rebuild-skill
1:1 rebuild of award-winning creative websites (WebGL / scroll-animation / portfolio sites).
awarexone/Agentic-Bug-Hunter
Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet.
lingbol088-spec/ReiPenFlow
Guided workflow for authorized penetration testing, vulnerability validation, security reporting, CTF/local sandbox reverse engineering, and user-directed vulnerability research.
Categories
A skill your agent uses whenever the user asks the running agent to gain a new capability — phrasings like "build a tool", "add a hook", "give yourself X", "let me <do thing through you", or…. Extend Harness is an agent skill from wedow/harness. Use whenever the user asks the running agent to gain a new capability — phrasings like "build a tool", "add a hook", "give yourself X", "let me <do thing through you", or anything that extends the agent itself at runtime.
Extend Harness fits situations like: the user asks the running agent to gain a new capability — phrasings like build a tool; give yourself X; let me <do thing through you; anything that extends the agent itself at runtime.
Run `npx skills add wedow/harness --skill extend-harness -a claude-code`. Or copy the skill folder (plugins/core/skills/extend-harness in wedow/harness) into .claude/skills/extend-harness in your project. Claude Code loads it when a task matches its description.
Run `npx skills add wedow/harness --skill extend-harness -a codex`. Or copy the skill folder (plugins/core/skills/extend-harness in wedow/harness) into .agents/skills/extend-harness in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add wedow/harness --skill extend-harness -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/extend-harness, .gemini/skills/extend-harness, .github/skills/extend-harness and .opencode/skills/extend-harness in your project.
Going by SKILL.md and its folder, Extend Harness needs the command-line tools its instructions call (jq and curl). Our summary lists: Python 3; A credential in MY_API_KEY.
SKILL.md names 1 domain. As links in the text: agents.md. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Extend Harness is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.4k tokens (SKILL.md is roughly 9.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Extend Harness: vphone600 Kernel Symbol Analysis (Lakr233/vphone-cli, 15k stars), Webhome Extension Builder (webhtv/webhtv, 1.7k stars), Reverse Flow (lingbol088-spec/reverse-flow-skill, 940 stars) and Website Rebuild (boyang-hu/website-rebuild-skill, 1.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
wedow (a GitHub user) maintains it in wedow/harness, which has 168 GitHub stars. The repository was last updated on October 7, 2026.
Source: wedow/harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.