harness-oia-audit
Composite Phase-2 audit worker (ADR-150). Bundles harness oia-manifest + threat-model + mcp-scan into one timestamped audit record stored in the `metaharness-audit` memory namespace. Designed for cron-scheduled drift detection.
How do I install this agent skill?
npx skills add https://github.com/ruvnet/ruflo --skill harness-oia-auditIs this agent skill safe to install?
- Gen Agent Trust Hubpass
The skill is a security auditing worker that bundles several static analysis tools to create composite audit records. It uses standard package execution and shell commands to perform its core auditing functions without any detected malicious patterns.
- Socketpass
No alerts
- Snykpass
Risk: LOW · No issues
What does this agent skill do?
The 13th worker (ADR-150 Phase 2) — runs three MetaHarness static surfaces in one shot, computes a composite worst-severity signal, and persists the audit record to memory so drift over time is visible.
Algorithm
Implementation: scripts/oia-audit.mjs.
- Run
harness oia-manifest <path>— Open Infrastructure Architecture layer alignment (L1-L9). - Run
harness threat-model <path>— categorized MCP-surface threat report withworst: clean|low|medium|high. - Run
harness mcp-scan <path>— per-server/tool policy + permissions- dep findings.
- Composite worst =
max(threatModel.worst, max(mcpScan.findings.severity)). - Persist payload to memory namespace
metaharness-auditwith keyaudit-<iso-timestamp>(unless--dry-run). --alert-on-worst <severity>: exit 1 if composite worst ≥ threshold.
Graceful degradation
When ALL three components report metaharness-not-available, the script
emits the standard degraded payload and exits 0. When only some are
degraded, each individual component carries its own degraded: true
flag in the audit record — the audit still runs and persists what it
could gather.
CI / cron integration
Designed for weekly cron in .github/workflows/:
on:
schedule:
- cron: '17 4 * * 0' # Sundays at 04:17 UTC
jobs:
oia-audit:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
- run: node plugins/ruflo-metaharness/scripts/oia-audit.mjs --alert-on-worst high
--alert-on-worst high fails the job on any HIGH-severity finding;
drift below HIGH is logged but doesn't block.
Memory namespace
Each audit run stores under metaharness-audit:audit-<iso-ts>. To list
recent audits:
npx @claude-flow/cli@latest memory list --namespace metaharness-audit --limit 10
To diff two audits (drift detection):
A=$(npx ... memory retrieve --key audit-2026-06-01... --namespace metaharness-audit)
B=$(npx ... memory retrieve --key audit-2026-06-15... --namespace metaharness-audit)
# Compare composite.worst, components.threatModel.worst, etc.
A future ADR can wire this into a dedicated cost-diff-style diff
viewer specifically for audit drift.
Pairs with
harness-threat-model— the underlying threat-model componentharness-mcp-scan— the underlying MCP-scan componentharness-score+harness-genome— readiness metrics (orthogonal to audit)
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/ruvnet/ruflo/harness-oia-audit">View harness-oia-audit on skillZs</a>