Security
AI coding harness composition orchestrator — manifest-described upstreams, composition skill workflows. Apache-2.0.
npx -y skills add easyinplay/harnessed --skill securityAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 2 stars2 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Stage ④.e verify sub-workflow — gstack /cso 安全审查 OWASP/auth/secrets (has_auth_or_secrets 触发, 可选 conditional; bundled verify-stage optional /cso step). schema_version: harnessed.workflow.v3 with disciplines_applied (6 default) + tools_available (gstack-cso) + 1 phase (gate ref has_auth_or_secrets conditional)。 Triggered by slash command `/verify-security` after `harnessed setup`.
SKILL.md
4.4 KB, ~1.0k tokens by cl100k_base, as published. Nobody here has run it
verify-security workflow (v3)
Overview
1-phase sub-workflow mapping CLAUDE.md "Verify 阶段 — 可选 /cso" onto harnessed runtime (Phase v3.0-3.4 W0.13b — D-04 Stage ④ Verify 7 sub + D-12 gstack 治理关卡 + Pattern A sub-workflow ship)。
| phase | id | upstream | model | capability | gate |
|---|---|---|---|---|---|
| 1 | 01-cso | gstack | opus | {{ capabilities.gstack-cso.cmd }} | judgments.stage-routing.verify-security-secrets.fires |
Per-phase config loads from workflows/verify/security/workflow.yaml; engine 4-level gate
resolver evaluates phase.has_auth_or_secrets == true via expr-eval — true 则 invoke gstack
/cso (OWASP / auth / credentials / secrets 全面审查), false 则 skip。
Capability refs
Sister workflows/capabilities.yaml entries:
gstack-cso— Bucket 3 治理关卡 (impl: gstack, cmd: /cso, fires_when: phase.stage == 'verify' AND phase.has_auth_or_secrets == true)
Gate ref
Sister workflows/judgments/stage-routing.yaml:
verify-security-secrets.fires—phase.stage == 'verify' and phase.has_auth_or_secrets == true
Routing rules
- ✅ 触发: auth flow / session / credentials / API keys / SQL injection 路径 / OWASP top 10 area
- ❌ 跳过: docs / 纯 UI styling / 内部 refactor / non-security PR
How to invoke
!harnessed checkpoint intent verify-security
The banner above (when present) means this invocation is REGISTERED with the engine (an intent marker) — not yet compliant: the steps below (prompt → spawn → checkpoint complete) resolve it, and a per-turn
<workflow-intent>reminder persists until they run.
The numbered sequence below is the state machine — execute it with Bash. Do NOT improvise an equivalent flow from the Overview above: freelancing bypasses the engine (no ledger, no evidence guard). harnessed gives you the spawn-ready prompt; YOU spawn the subagent with a CC-native Task / Agent tool (keeps the session responsive + lets clarification round-trips reach the user).
Do NOT pipe to harnessed run verify-security — that is the CI/headless path (in-process SDK spawn
that blocks the session inside Claude Code).
- Bash:
harnessed prompt verify-security --task "$ARGUMENTS" --json→ parse{prompt, max_iterations, model}. - Spawn a CC-native subagent (Task / Agent tool) with that
prompt+model, wrapped in the ralph-loop plugin:/ralph-loop "<prompt>" --max-iterations <max_iterations> --completion-promise "COMPLETE". If the plugin is absent, use the native goal gate instead (Claude Code 2.1.139+ / Codex):/goal "this subtask is delivered: the subagent's final output contains verbatim <promise>COMPLETE</promise>; or stop after <max_iterations> turns"then spawn the subagent and let the goal evaluator drive re-spawns until it clears. If/goalis unavailable too, self-loop: spawn → check output for<promise>COMPLETE</promise>→ re-spawn with prior output appended (up to max_iterations). Set the goal only at the leaf subtask level —/goalis single-slot per session and a nested goal overwrites the outer one. - If the output contains
STATUS: NEEDS_CLARIFICATION+ a question list: STOP, relay them verbatim via AskUserQuestion, append the answers to the spec, then re-spawn the same sub. - On
<promise>COMPLETE</promise>: Bashharnessed checkpoint complete verify-security --summary "<one-line>". The evidence guard runs here (fail-CLOSED): if a declaredartifacts_expectedfile is missing it exits non-zero — re-spawn to produce it before treating the sub as done.
References
- D-04 Stage ④ Verify 7 sub 分解
- D-12 gstack 治理关卡可选
- workflows/capabilities.yaml — gstack-cso
- workflows/judgments/stage-routing.yaml — verify-security-secrets trigger
- workflows/verify-work/workflow.yaml v2 SHIPPED phase 06-cso-conditional sister verbatim
What ships with it: 2 files
6.6 KB alongside SKILL.md
- SKILL.zh-Hans.md4.9 KB
- workflow.yaml1.7 KB