Agent skill

Extend Harness

by wedow in wedow/harness

A skill your agent uses whenever the user asks the running agent to gain a new capability — phrasings like "build a tool", "add a hook", "give yourself X", "let me <do thing through you", or…

MITAuto-check passedSecurity

Install Extend Harness

skills CLI
$ npx skills add wedow/harness --skill extend-harness -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install wedow/harness extend-harness --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/wedow/harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/core/skills/extend-harness .claude/skills/extend-harness && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
extend-harness
GitHub stars
168
Token cost
~2.4k tokens
SKILL.md length
923 words
Files
1
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses whenever the user asks the running agent to gain a new capability — phrasings like "build a tool", "add a hook", "give yourself X", "let me <do thing through you", or…

  • Works in 5 steps: Decide scope (~/.harness/ for personal,… → Write the executable with the right… → chmod +x — non-executable files are… → …
  • The user asks the running agent to gain a new capability — phrasings like build a tool
  • SKILL.md covers Where to put extensions, Tools (the most common…, Hooks (the agent loop is a… and Skills (on-demand instruction…, plus 4 more sections
  • Calls jq and curl

What it does

Extend Harness is an agent skill from wedow/harness. Use whenever the user asks the running agent to gain a new capability — phrasings like "build a tool", "add a hook", "give yourself X", "let me <do thing through you", or anything that extends the agent itself at runtime. Defines the plugin protocols, where to install them (.harness/ scopes), and the required test-through-tool-call iteration pattern. CRITICAL: "tool" here means a plugin the agent invokes via tool-calls — install it to a .harness/ directory; do NOT write a standalone CLI script in the working…

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Reverse engineering and malware. The repository describes itself as: Minimal agent loop in bash. Pure state follower core with plugin-based tools, hooks, providers, and commands. Dependencies: bash 4+, jq, curl. The licence is MIT.

When your agent uses it

  • The user asks the running agent to gain a new capability — phrasings like build a tool
  • Give yourself X
  • Let me <do thing through you
  • Anything that extends the agent itself at runtime

Example prompts

  • “build a tool”
  • “add a hook”
  • “give yourself X”
  • “/extend-harness”

Requirements

  • Python 3
  • A credential in MY_API_KEY

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Decide scope (~/.harness/ for personal, /.harness/ for shared).
  2. Write the executable with the right protocol — use write_file, not heredoc-via-bash, so the file is clean and easy to edit later.
  3. chmod +x — non-executable files are silently ignored. This is the most common omission.
  4. Verify by invoking the new extension as a real tool call on your next turn. Harness rediscovers tools every loop iteration, so the new…
  5. Iterate on failure. If the result is an error or unexpected output, read it, edit the file with edit_file/write_file, and call again. Keep…

What it can do on your machine

Read from SKILL.md and the folder at commit 5f5d968. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • jq
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • agents.md

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Extend Harness loads about 2.4k tokens when it runs. Until then it costs about 175 tokens; SKILL.md has 923 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~175
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from wedow/harness at commit 5f5d968, republished under its MIT licence (© wedow). 923 words, ~2,431 tokens.

Download SKILL.mdSave it as .claude/skills/extend-harness/SKILL.md (or your agent's skills folder).
name
extend-harness
description
Use whenever the user asks the running agent to gain a new capability — phrasings like "build a tool", "add a hook", "give yourself X", "let me <do thing> through you", or anything that extends the agent itself at runtime. Defines the plugin protocols, where to install them (.harness/ scopes), and the required test-through-tool-call iteration pattern. CRITICAL: "tool" here means a plugin the agent invokes via tool-calls — install it to a .harness/ directory; do NOT write a standalone CLI script in the working directory and do NOT modify the harness codebase under plugins/. Load this skill before acting on such a request rather than reverse-engineering the protocol from source.

Extending harness

Harness is a state follower; everything else is plugins discovered at runtime from .harness/ directories. To extend the running agent — yourself — drop an executable into the right place. The next loop iteration picks it up; no restart needed (_refresh_sources runs every turn).

Where to put extensions

Discovery walks from CWD up to /, collecting every .harness/ directory. For same-named files, most-local wins. Pick scope based on lifetime and audience:

ScopeLocationUse when
User-global~/.harness/Available everywhere; personal preferences, secrets
Project<repo>/.harness/Committed with the repo, scoped to that project
Subdir<dir>/.harness/Narrower scope inside a monorepo

Inside any .harness/:

commands/         # CLI subcommands (hs <name>)
tools/            # tools the model can call
hooks.d/<stage>/  # pipeline hooks; sorted by NN- prefix
providers/        # LLM API adapters (binary or .conf variant)
prompts/*.md      # appended to the system prompt
skills/<name>/    # on-demand instruction packs (SKILL.md)
plugins/<name>/   # plugin packs with the same layout

AGENTS.md follows the agents.md standard — placed at the parent of the .harness/ directory, not inside it.

Tools (the most common extension)

A tool is an executable responding to three flags. Drop it at .harness/tools/<name> and chmod +x.

bash
#!/usr/bin/env bash
set -euo pipefail
case "${1:-}" in
  --schema) cat <<'JSON'
{"name":"web_get","description":"GET a URL and return body",
 "input_schema":{"type":"object",
                 "properties":{"url":{"type":"string"}},
                 "required":["url"]}}
JSON
    ;;
  --describe) echo "GET a URL" ;;
  --exec)
    url="$(jq -r '.url' < /dev/stdin)"
    curl -fsS "$url"
    ;;
esac
  • Stdout becomes the tool result. Stderr → HARNESS_LOG. Non-zero exit marks the result as error: true.
  • Tools run in HARNESS_CWD (the session's original working directory).
  • Any language: see ../../../../examples/tools/web_fetch for a Python example.

Verify: hs tools lists what's discovered.

Hooks (the agent loop is a pipeline)

Each stage dispatches its hooks as a chain — each hook reads the previous one's stdout and writes JSON. The numeric NN- prefix sets order. Local same-basename overrides global, which lets you replace a bundled hook by name.

start → assemble → send → receive → done
                    ↑                 │
                    │   tool_exec → tool_done
                    │                 │
                    └─────────────────┘

The transition is not hardcoded — each hook may emit next_state and the loop follows it. Empty next_state ends the loop. output (string) is what's printed when the loop exits.

StageStdinDefault nextUse for
sources{}(n/a)Discover/filter plugin source dirs
resolve{provider,model}(n/a)Pick provider/model before the loop
start{}assembleSession init (e.g. set HARNESS_CWD)
assemble{}sendBuild payload (messages, tools, system)
sendpayloadreceiveCall provider
receiveAPI responsedoneSave assistant msg, extract tool calls
tool_exec{tool_calls:[…]}tool_doneExecute one tool call
tool_donetool resulttool_exec / assembleSave result, route
errorerror context(empty=stop)Recover or report
donefinal context(empty=stop)Cleanup, terminal

Pipeline rules:

  • All hooks for a stage run in basename-sorted order (use NN- prefix).
  • Non-zero exit aborts the chain → routes to error.
  • Pass-through hooks (gates, observers) just cat stdin to stdout after side effects, leaving the pipeline payload intact.
  • The hook that wants to drive a transition emits {"next_state": "..."} (usually the last hook in the stage).

Example — confirm bash before execution (gate hook on tool_exec):

bash
#!/usr/bin/env bash
# .harness/hooks.d/tool_exec/05-confirm
set -euo pipefail
tc="$(cat)"
[[ "$(echo "$tc" | jq -r '.name')" == "bash" ]] || { echo "$tc"; exit 0; }
cmd="$(echo "$tc" | jq -r '.input.command')"
read -p "run: $cmd ? [y/N] " r </dev/tty
[[ "$r" =~ ^[Yy] ]] || exit 1
echo "$tc"

Example — log token usage after each response (observer hook on receive):

bash
#!/usr/bin/env bash
# .harness/hooks.d/receive/20-cost
set -euo pipefail
r="$(cat)"
in="$(echo "$r" | jq -r '.usage.input_tokens // 0')"
out="$(echo "$r" | jq -r '.usage.output_tokens // 0')"
echo "$(date -Iseconds) in=$in out=$out" >> "${HARNESS_SESSION}/cost.log"
echo "$r"   # pass through

Verify: hs hooks <stage> lists what's discovered.

Skills (on-demand instruction packs)

A skill is a directory under .harness/skills/<name>/ containing SKILL.md with YAML frontmatter (name, description). The 35-skills assemble hook injects only the catalog (name + description) into the system prompt — the model loads the full body via the skill tool when relevant. Optional sibling dirs (references/, scripts/, assets/) are listed so the model knows what auxiliary files exist.

.harness/skills/my-workflow/
  SKILL.md                # frontmatter + body
  references/details.md   # listed in <skill-resources>
  scripts/setup.sh        # listed in <skill-resources>

Use a skill when instructions would bloat the system prompt but only matter for specific tasks. The description field is what triggers the model — make it concrete about when to load it.

Providers

A provider is an executable in providers/<name> reading payload JSON on stdin and writing the raw API response. Optional flags: --describe, --ready (exit 0 if creds set; used for auto-select), --defaults (model=… lines), --env, --stream.

A directory whose basename matches a binary in its providers/ (e.g. plugins/openai/providers/openai) is treated as a provider plugin — its hooks/tools/prompts only participate when that provider is active.

For OpenAI-compatible or Anthropic-compatible services, write a <name>.conf instead of a full binary:

protocol=openai
description=My Endpoint
model=foo-1
url=https://api.example.com/v1/chat/completions
auth_env=MY_API_KEY

Drop in any providers/ dir; hs auth set <name> stores credentials under that name.

Show full SKILL.md (332 more words)Show less

Prompts

AGENTS.md files (at each .harness/ parent) are concatenated into the system prompt, global → local. For composable fragments inside .harness/, use prompts/*.md (sorted by filename, all loaded). Local fragments come last so they can refine global ones.

Workflow for self-extension

  1. Decide scope (~/.harness/ for personal, <repo>/.harness/ for shared).
  2. Write the executable with the right protocol — use write_file, not heredoc-via-bash, so the file is clean and easy to edit later.
  3. chmod +x — non-executable files are silently ignored. This is the most common omission.
  4. Verify by invoking the new extension as a real tool call on your next turn. Harness rediscovers tools every loop iteration, so the new tool is already registered — make a tool call to it the same way you call read_file or bash. Listing it with hs tools only proves discovery, not that the protocol implementation is correct; you must actually invoke it. For hooks, trigger the relevant stage (e.g. emit a tool call to exercise tool_exec). For commands, run hs <name> from bash. Never test a tool by shelling out (./tool --exec <<< '{...}') or by exiting back to the user with "ready to use" — both bypass the JSON dispatcher and silently skip protocol bugs (bad schema, wrong stdout shape, schema/exec mismatch, forgotten chmod +x).
  5. Iterate on failure. If the result is an error or unexpected output, read it, edit the file with edit_file/write_file, and call again. Keep iterating until a real tool call returns the expected result. The task is not done until you have personally invoked the new extension through the loop and seen the right result — do not return control to the user with the extension untested.

Going deeper

© wedow, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/core/skills/extend-harness of wedow/harness.

Open the folder on GitHubat commit 5f5d968

Compare with similar skills

Extend Harness next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Extend Harness compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Extend Harness this skillwedow/harness168—~2.4kAutomated safety check: PassMIT
vphone600 Kernel Symbol AnalysisLakr233/vphone-cli15k—~530Automated safety check: PassMIT
Webhome Extension Builderwebhtv/webhtv1.7k—~2.8kAutomated safety check: PassGPL-3.0
Reverse Flowlingbol088-spec/reverse-flow-skill940—~2.4kAutomated safety check: PassMIT
Website Rebuildboyang-hu/website-rebuild-skill1.4k—~6.1kAutomated safety check: PassMIT
Client Request Signature Reversalawarexone/Agentic-Bug-Hunter5.3k—~4.7kAutomated safety check: PassMIT

Similar skills

  • Looks up symbols and addresses in vphone600 release and research kernel datasets, and cross-references XNU source, with findings that separate fact from inference.

    15k GitHub stars~530 tokensUpdated today
    SecurityAuto-check passed
  • Build, review, debug, reverse-engineer, and package WebHome injected extension scripts for FongMi/WebHome App WebView pages.

    1.7k GitHub stars~2.8k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Reverse Flow

    lingbol088-spec/reverse-flow-skill

    Guided reverse engineering workflow for binaries, firmware, mobile apps, scripts, document samples, protocol captures, and unknown artifacts.

    940 GitHub stars~2.4k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Website Rebuild

    boyang-hu/website-rebuild-skill

    1:1 rebuild of award-winning creative websites (WebGL / scroll-animation / portfolio sites).

    1.4k GitHub stars~6.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Client Request Signature Reversal

    awarexone/Agentic-Bug-Hunter

    Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet.

    5.3k GitHub stars~4.7k tokensUpdated yesterday
    SecurityAuto-check passed
  • Penetration Flow

    lingbol088-spec/ReiPenFlow

    Guided workflow for authorized penetration testing, vulnerability validation, security reporting, CTF/local sandbox reverse engineering, and user-directed vulnerability research.

    222 GitHub stars~1.8k tokensUpdated 2 mo ago
    SecurityAuto-check passed

Categories

Questions about Extend Harness

What does Extend Harness do?

A skill your agent uses whenever the user asks the running agent to gain a new capability — phrasings like "build a tool", "add a hook", "give yourself X", "let me <do thing through you", or…. Extend Harness is an agent skill from wedow/harness. Use whenever the user asks the running agent to gain a new capability — phrasings like "build a tool", "add a hook", "give yourself X", "let me <do thing through you", or anything that extends the agent itself at runtime.

When should I use Extend Harness?

Extend Harness fits situations like: the user asks the running agent to gain a new capability — phrasings like build a tool; give yourself X; let me <do thing through you; anything that extends the agent itself at runtime.

How do I install Extend Harness in Claude Code?

Run `npx skills add wedow/harness --skill extend-harness -a claude-code`. Or copy the skill folder (plugins/core/skills/extend-harness in wedow/harness) into .claude/skills/extend-harness in your project. Claude Code loads it when a task matches its description.

How do I install Extend Harness in Codex?

Run `npx skills add wedow/harness --skill extend-harness -a codex`. Or copy the skill folder (plugins/core/skills/extend-harness in wedow/harness) into .agents/skills/extend-harness in your project. Codex loads it when a task matches its description.

Can I use Extend Harness in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add wedow/harness --skill extend-harness -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/extend-harness, .gemini/skills/extend-harness, .github/skills/extend-harness and .opencode/skills/extend-harness in your project.

What does Extend Harness need to run?

Going by SKILL.md and its folder, Extend Harness needs the command-line tools its instructions call (jq and curl). Our summary lists: Python 3; A credential in MY_API_KEY.

Does Extend Harness access the network?

SKILL.md names 1 domain. As links in the text: agents.md. This is read from the text; nothing was executed.

Is Extend Harness safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Extend Harness use?

Extend Harness is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Extend Harness use?

About 2.4k tokens (SKILL.md is roughly 9.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Extend Harness?

Skills that share tags, products or a category with Extend Harness: vphone600 Kernel Symbol Analysis (Lakr233/vphone-cli, 15k stars), Webhome Extension Builder (webhtv/webhtv, 1.7k stars), Reverse Flow (lingbol088-spec/reverse-flow-skill, 940 stars) and Website Rebuild (boyang-hu/website-rebuild-skill, 1.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Extend Harness?

wedow (a GitHub user) maintains it in wedow/harness, which has 168 GitHub stars. The repository was last updated on October 7, 2026.

Source: wedow/harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.