/harness-oia-audit
Composite Phase-2 audit worker (ADR-150). Bundles harness oia-manifest + threat-model + mcp-scan into one timestamped audit record stored in the `metaharness-audit` memory namespace. Designed for cron-scheduled drift detection.
$ npx -y skills add ruvnet/ruflo --skill harness-oia-audit --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
- You can call itInvoke it directly when you want it.
- Slash command
/harness-oia-audit
Context preview
The summary Claude sees to decide when to auto-load this skill.
Composite Phase-2 audit worker (ADR-150). Bundles harness oia-manifest + threat-model + mcp-scan into one timestamped audit record stored in the `metaharness-audit` memory namespace. Designed for cron-scheduled drift detection.
SKILL.md
harness-oia-audit.SKILL.mdname: harness-oia-audit
description: Composite Phase-2 audit worker (ADR-150). Bundles harness oia-manifest + threat-model + mcp-scan into one timestamped audit record stored in the `metaharness-audit` memory namespace. Designed for cron-scheduled drift detection.
argument-hint: "[--path .] [--dry-run] [--alert-on-worst clean|low|medium|high] [--format table|json]"
allowed-tools: Bash
The 13th worker (ADR-150 Phase 2) — runs three MetaHarness static surfaces in one shot, computes a composite worst-severity signal, and persists the audit record to memory so drift over time is visible.
Algorithm
Implementation: [`scripts/oia-audit.mjs`](../../scripts/oia-audit.mjs).
1. Run `harness oia-manifest <path>` — Open Infrastructure Architecture layer alignment (L1-L9). 2. Run `harness threat-model <path>` — categorized MCP-surface threat report with `worst: clean|low|medium|high`. 3. Run `harness mcp-scan <path>` — per-server/tool policy + permissions
- dep findings.
4. Composite worst = `max(threatModel.worst, max(mcpScan.findings.severity))`. 5. Persist payload to memory namespace `metaharness-audit` with key `audit-<iso-timestamp>` (unless `--dry-run`). 6. `--alert-on-worst <severity>`: exit 1 if composite worst ≥ threshold.
Graceful degradation
When ALL three components report `metaharness-not-available`, the script emits the standard degraded payload and exits 0. When only some are degraded, each individual component carries its own `degraded: true` flag in the audit record — the audit still runs and persists what it could gather.
CI / cron integration
Designed for weekly cron in `.github/workflows/`:
on:
schedule:
- cron: '17 4 * * 0' # Sundays at 04:17 UTC
jobs:
oia-audit:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
- run: node plugins/ruflo-metaharness/scripts/oia-audit.mjs --alert-on-worst high`--alert-on-worst high` fails the job on any HIGH-severity finding; drift below HIGH is logged but doesn't block.
Memory namespace
Each audit run stores under `metaharness-audit:audit-<iso-ts>`. To list recent audits:
npx @claude-flow/cli@latest memory list --namespace metaharness-audit --limit 10
To diff two audits (drift detection):
A=$(npx ... memory retrieve --key audit-2026-06-01... --namespace metaharness-audit)
B=$(npx ... memory retrieve --key audit-2026-06-15... --namespace metaharness-audit)
# Compare composite.worst, components.threatModel.worst, etc.
A future ADR can wire this into a dedicated `cost-diff`-style diff viewer specifically for audit drift.
Pairs with
- `harness-threat-model` — the underlying threat-model component
- `harness-mcp-scan` — the underlying MCP-scan component
- `harness-score` + `harness-genome` — readiness metrics (orthogonal to audit)
Read more
name: harness-oia-audit description: Composite Phase-2 audit worker (ADR-150). Bundles harness oia-manifest + threat-model + mcp-scan into one timestamped audit record stored in the `metaharness-audit` memory namespace. Designed for cron-scheduled drift detection. argument-hint: "[--path .] [--dry-run] [--alert-on-worst clean|low|medium|high] [--format table|json]" allowed-tools: Bash
The 13th worker (ADR-150 Phase 2) — runs three MetaHarness static surfaces in one shot, computes a composite worst-severity signal, and persists the audit record to memory so drift over time is visible.
Algorithm
Implementation: [`scripts/oia-audit.mjs`](../../scripts/oia-audit.mjs).
1. Run `harness oia-manifest <path>` — Open Infrastructure Architecture layer alignment (L1-L9). 2. Run `harness threat-model <path>` — categorized MCP-surface threat report with `worst: clean|low|medium|high`. 3. Run `harness mcp-scan <path>` — per-server/tool policy + permissions
- dep findings.
4. Composite worst = `max(threatModel.worst, max(mcpScan.findings.severity))`. 5. Persist payload to memory namespace `metaharness-audit` with key `audit-<iso-timestamp>` (unless `--dry-run`). 6. `--alert-on-worst <severity>`: exit 1 if composite worst ≥ threshold.
Graceful degradation
When ALL three components report `metaharness-not-available`, the script emits the standard degraded payload and exits 0. When only some are degraded, each individual component carries its own `degraded: true` flag in the audit record — the audit still runs and persists what it could gather.
CI / cron integration
Designed for weekly cron in `.github/workflows/`:
on:
schedule:
- cron: '17 4 * * 0' # Sundays at 04:17 UTC
jobs:
oia-audit:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
- run: node plugins/ruflo-metaharness/scripts/oia-audit.mjs --alert-on-worst high`--alert-on-worst high` fails the job on any HIGH-severity finding; drift below HIGH is logged but doesn't block.
Memory namespace
Each audit run stores under `metaharness-audit:audit-<iso-ts>`. To list recent audits:
npx @claude-flow/cli@latest memory list --namespace metaharness-audit --limit 10
To diff two audits (drift detection):
A=$(npx ... memory retrieve --key audit-2026-06-01... --namespace metaharness-audit) B=$(npx ... memory retrieve --key audit-2026-06-15... --namespace metaharness-audit) # Compare composite.worst, components.threatModel.worst, etc.
A future ADR can wire this into a dedicated `cost-diff`-style diff viewer specifically for audit drift.
Pairs with
- `harness-threat-model` — the underlying threat-model component
- `harness-mcp-scan` — the underlying MCP-scan component
- `harness-score` + `harness-genome` — readiness metrics (orthogonal to audit)
An agent meta-harness for Claude Code and Codex. Agent = Model + Harness. The model writes; the harness gives it tools, memory, loops, sandboxes, and controls so it can actually work.
Repo: ruvnet/ruflo
Other skills on claude-flow.
- /agentdb-advanced
Master advanced AgentDB features including QUIC synchronization, multi-database management, custom distance metrics, hybrid search, and distributed systems integration. Use when building distributed AI systems, multi-agent coordination, or advanced vector search applications.
Open skill - /agentdb-learning
Create and train AI learning plugins with AgentDB's 9 reinforcement learning algorithms. Includes Decision Transformer, Q-Learning, SARSA, Actor-Critic, and more. Use when building self-learning agents, implementing RL, or optimizing agent behavior through experience.
Open skill - /agentdb-memory-patterns
Implement persistent memory patterns for AI agents using AgentDB. Includes session memory, long-term storage, pattern learning, and context management. Use when building stateful agents, chat systems, or intelligent assistants.
Open skill - /agentdb-optimization
Optimize AgentDB performance with quantization (4-32x memory reduction), HNSW indexing (150x faster search), caching, and batch operations. Use when optimizing memory usage, improving search speed, or scaling to millions of vectors.
Open skill - /agentdb-vector-search
Implement semantic vector search with AgentDB for intelligent document retrieval, similarity matching, and context-aware querying. Use when building RAG systems, semantic search engines, or intelligent knowledge bases.
Open skill - /agentic-jujutsu
Quantum-resistant, self-learning version control for AI agents with ReasoningBank intelligence and multi-agent coordination
Open skill

