harness-mcp-scan
Static security scan of a harness's declared MCP surface via `harness mcp-scan <path>`. Reads `.mcp/servers.json` + `.harness/claims.json`. Pure-read, no dispatch. Exits 1 on findings at or above `--fail-on` severity.
How do I install this agent skill?
npx skills add https://github.com/ruvnet/ruflo --skill harness-mcp-scanIs this agent skill safe to install?
- Gen Agent Trust Hubpass
The skill performs a static security scan on local configuration files using the metaharness tool. No malicious behaviors were detected.
- Socketpass
No alerts
- Snykpass
Risk: LOW · No issues
What does this agent skill do?
Calls harness mcp-scan to enumerate every declared MCP server + tool
and flag policy / permission / dependency issues. Never executes any
tool; pure static analysis.
Algorithm
Implementation: scripts/mcp-scan.mjs.
- Invoke the pinned
harnessbinary (metaharness@~0.4.1, resolved from a local install or the one-time~/.ruflo/metaharness-cache-<pin>cache — never@latest):harness mcp-scan <path> --json. - Parse
findings[]with{ severity, id, server, tool, message }. --fail-on <severity>: exit 1 when any finding is at or above that level. Defaulthigh.- Output JSON (default) or markdown table.
Severity rank
| Severity | Rank |
|---|---|
| low | 1 |
| medium | 2 |
| high | 3 |
--fail-on high (default) only fails on HIGH; --fail-on medium also
fails on MEDIUM; --fail-on low fails on any finding.
CI integration
- name: MCP static scan
run: node plugins/ruflo-metaharness/scripts/mcp-scan.mjs --fail-on high
The exit code is the only thing CI watches; the JSON output goes to artifacts for human review.
Graceful degradation
When harness binary is unavailable (no network, blocked registry),
emits structured { degraded: true, reason: 'metaharness-not-available' }
and exits 0. Ruflo continues — ADR-150 architectural constraint.
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/ruvnet/ruflo/harness-mcp-scan">View harness-mcp-scan on skillZs</a>