/harness-mcp-scan
Static security scan of a harness's declared MCP surface via `harness mcp-scan <path>`. Reads `.mcp/servers.json` + `.harness/claims.json`. Pure-read, no dispatch. Exits 1 on findings at or above `--fail-on` severity.
$ npx -y skills add ruvnet/ruflo --skill harness-mcp-scan --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
- You can call itInvoke it directly when you want it.
- Slash command
/harness-mcp-scan
Context preview
The summary Claude sees to decide when to auto-load this skill.
Static security scan of a harness's declared MCP surface via `harness mcp-scan <path>`. Reads `.mcp/servers.json` + `.harness/claims.json`. Pure-read, no dispatch. Exits 1 on findings at or above `--fail-on` severity.
SKILL.md
harness-mcp-scan.SKILL.mdname: harness-mcp-scan
description: Static security scan of a harness's declared MCP surface via `harness mcp-scan <path>`. Reads `.mcp/servers.json` + `.harness/claims.json`. Pure-read, no dispatch. Exits 1 on findings at or above `--fail-on` severity.
argument-hint: "[--path .] [--fail-on low|medium|high] [--format table|json]"
allowed-tools: Bash
Calls `harness mcp-scan` to enumerate every declared MCP server + tool and flag policy / permission / dependency issues. Never executes any tool; pure static analysis.
Algorithm
Implementation: [`scripts/mcp-scan.mjs`](../../scripts/mcp-scan.mjs).
1. Invoke the pinned `harness` binary (`metaharness@~0.3.0`, resolved from a local install or the one-time `~/.ruflo/metaharness-cache-<pin>` cache — never `@latest`): `harness mcp-scan <path> --json`. 2. Parse `findings[]` with `{ severity, id, server, tool, message }`. 3. `--fail-on <severity>`: exit 1 when any finding is at or above that level. Default `high`. 4. Output JSON (default) or markdown table.
Severity rank
| Severity | Rank | |---|---:| | low | 1 | | medium | 2 | | high | 3 |
`--fail-on high` (default) only fails on HIGH; `--fail-on medium` also fails on MEDIUM; `--fail-on low` fails on any finding.
CI integration
- name: MCP static scan
run: node plugins/ruflo-metaharness/scripts/mcp-scan.mjs --fail-on high
The exit code is the only thing CI watches; the JSON output goes to artifacts for human review.
Graceful degradation
When `harness` binary is unavailable (no network, blocked registry), emits structured `{ degraded: true, reason: 'metaharness-not-available' }` and exits 0. Ruflo continues — ADR-150 architectural constraint.
Read more
name: harness-mcp-scan description: Static security scan of a harness's declared MCP surface via `harness mcp-scan <path>`. Reads `.mcp/servers.json` + `.harness/claims.json`. Pure-read, no dispatch. Exits 1 on findings at or above `--fail-on` severity. argument-hint: "[--path .] [--fail-on low|medium|high] [--format table|json]" allowed-tools: Bash
Calls `harness mcp-scan` to enumerate every declared MCP server + tool and flag policy / permission / dependency issues. Never executes any tool; pure static analysis.
Algorithm
Implementation: [`scripts/mcp-scan.mjs`](../../scripts/mcp-scan.mjs).
1. Invoke the pinned `harness` binary (`metaharness@~0.3.0`, resolved from a local install or the one-time `~/.ruflo/metaharness-cache-<pin>` cache — never `@latest`): `harness mcp-scan <path> --json`. 2. Parse `findings[]` with `{ severity, id, server, tool, message }`. 3. `--fail-on <severity>`: exit 1 when any finding is at or above that level. Default `high`. 4. Output JSON (default) or markdown table.
Severity rank
| Severity | Rank | |---|---:| | low | 1 | | medium | 2 | | high | 3 |
`--fail-on high` (default) only fails on HIGH; `--fail-on medium` also fails on MEDIUM; `--fail-on low` fails on any finding.
CI integration
- name: MCP static scan run: node plugins/ruflo-metaharness/scripts/mcp-scan.mjs --fail-on high
The exit code is the only thing CI watches; the JSON output goes to artifacts for human review.
Graceful degradation
When `harness` binary is unavailable (no network, blocked registry), emits structured `{ degraded: true, reason: 'metaharness-not-available' }` and exits 0. Ruflo continues — ADR-150 architectural constraint.
An agent meta-harness for Claude Code and Codex. Agent = Model + Harness. The model writes; the harness gives it tools, memory, loops, sandboxes, and controls so it can actually work.
Repo: ruvnet/ruflo
Other skills on claude-flow.
- /agentdb-advanced
Master advanced AgentDB features including QUIC synchronization, multi-database management, custom distance metrics, hybrid search, and distributed systems integration. Use when building distributed AI systems, multi-agent coordination, or advanced vector search applications.
Open skill - /agentdb-learning
Create and train AI learning plugins with AgentDB's 9 reinforcement learning algorithms. Includes Decision Transformer, Q-Learning, SARSA, Actor-Critic, and more. Use when building self-learning agents, implementing RL, or optimizing agent behavior through experience.
Open skill - /agentdb-memory-patterns
Implement persistent memory patterns for AI agents using AgentDB. Includes session memory, long-term storage, pattern learning, and context management. Use when building stateful agents, chat systems, or intelligent assistants.
Open skill - /agentdb-optimization
Optimize AgentDB performance with quantization (4-32x memory reduction), HNSW indexing (150x faster search), caching, and batch operations. Use when optimizing memory usage, improving search speed, or scaling to millions of vectors.
Open skill - /agentdb-vector-search
Implement semantic vector search with AgentDB for intelligent document retrieval, similarity matching, and context-aware querying. Use when building RAG systems, semantic search engines, or intelligent knowledge bases.
Open skill - /agentic-jujutsu
Quantum-resistant, self-learning version control for AI agents with ReasoningBank intelligence and multi-agent coordination
Open skill

