verify
Verify harness changes end-to-end without docker — drive the real pinned CLI against a header-capturing stub server with the exact env resolve_auth_env() produces.
How do I install this agent skill?
npx skills add https://github.com/anthropics/defending-code-reference-harness --skill verifyIs this agent skill safe to install?
- Gen Agent Trust Hubpass
This skill provides a procedure for verifying harness changes in a local environment. It utilizes vendor-specific tools and standard development practices, such as package installation and environment variable configuration, to emulate a containerized environment for testing purposes.
- Socketwarn
1 alert: gptAnomaly
- Snykpass
Risk: LOW · No issues
What does this agent skill do?
Verifying harness changes on a docker-less host
The pipeline's real surface is the in-container claude -p process and its
outbound API requests. Without docker, drive the same pinned CLI binary
directly with the env dict the harness would inject via docker -e.
Recipe
- Get the pinned CLI (version from
harness/agent_image.py:CLAUDE_CODE_VERSION):npm install --no-save @anthropic-ai/claude-code@<pin>in a temp dir → binary atnode_modules/@anthropic-ai/claude-code/bin/claude.exe(the.exename is the real native-binary entry on Linux too, filled in by the package's postinstall — not a Windows leftover). - Stub API server: a tiny HTTP server that appends each request's
headers to a JSONL file and returns a 400
invalid_request_error(non-retryable, so the CLI exits fast; exit=1 is expected). - Build the agent env exactly as the pipeline does:
python3 -c "from harness.auth import resolve_auth_env; ..."and dump to anexport-lines file withshlex.quote(values contain newlines — NEVER pass viaenv $(...), word-splitting mangles them;sourcethe file). - Emulate the container env:
unset ANTHROPIC_CUSTOM_HEADERS(and any other ambient var not in the resolved dict) before sourcing — a Claude Code session in this repo injects.claude/settings.jsonenv into shells, which containers never see. - Run:
ANTHROPIC_BASE_URL=http://127.0.0.1:<port> CLAUDECODE= IS_SANDBOX=1 timeout 30 <cli> -p hi --model claude-sonnet-4-5 --max-turns 1, then read the captured JSONL.
Gotchas
- Unit tests in
tests/test_patch.py/tests/test_patch_grade.pyneed docker and fail on docker-less hosts — pre-existing, not your change. - The docker
-einjection leg itself can't be exercised without docker; it's the same mechanism that carriesANTHROPIC_API_KEYin production. - For the interactive-skills surface, copy
.claude/settings.jsoninto a fresh temp dir and run the hostclaudefrom there (with ambientANTHROPIC_CUSTOM_HEADERSunset so settings.json is the only source).
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/anthropics/defending-code-reference-harness/verify">View verify on skillZs</a>