Agent skill · Security

harness-threat-model

Enterprise-review-grade threat model from `harness threat-model <path>`. Categorizes MCP-surface threats; emits `worst: 'clean'|'low'|'medium'|'high'` + per-threat findings. Pure-read.

rUv71,307★ · +1,002/wk · 3 repos on radarProfile →
claude-codecodexcan modify filesMIT
Install
npx skills add ruvnet/ruflo --skill harness-threat-model --agent claude-code

Same command for any agent — swap --agent for codex, cursor, copilot.

Facts
Files in the skill folder: 1
SKILL.md size: 1 KB
Bundled scripts: none
Allowed tools: Bash
Path: plugins/ruflo-metaharness/skills/harness-threat-model/SKILL.md
Open the folder on GitHub →
Where it comes from
Source: ruvnet/ruflo
Stars: 67,015 · +629 this week
Language: TypeScript
Read our review of the source →

Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.

From the SKILL.md

The companion to `harness-mcp-scan` for enterprise security reviews. Where mcp-scan is a per-server static lint, threat-model produces a categorized report suitable for sharing with an InfoSec team. ## Algorithm Implementation: [`scripts/threat-model.mjs`](../../scripts/threat-model.mjs). 1. Invoke the pinned `harness` binary (`metaharness@~0.3.0`, resolved from a local install or the one-time `~/.ruflo/metaharness-cache-<pin>` cache — never `@latest`): `harness threat-model <path> --json`. 2. Parse `{ worst, findings[] }`. 3. `--fail-on <severity>`: exit 1 when `worst >= fail-on`. Default `high`. ## Severity rank | Severity | Rank | |---|---:| | clean | 0 | | low | 1 | | medium | 2 | | high | 3 | ## When to use - Pre-launch review: include the JSON output in the release-readiness packet sent to security. - Periodic audit: schedule via the planned `oia-audit` background worker (ADR-150 Phase 2) to detect MCP-surface drift. ## Graceful degradation Same pattern as the other skills: when `harness` is absent, emit `{ degraded: true }` and exit 0. ADR-150 architectural constraint.

What's inside
Steps it walks through
  1. Algorithm
  2. Severity rank
  3. When to use
  4. Graceful degradation
More from ruflo
All skills →
About this skill
What does the harness-threat-model skill do?

Enterprise-review-grade threat model from `harness threat-model <path>`. Categorizes MCP-surface threats; emits `worst: 'clean'|'low'|'medium'|'high'` + per-threat findings. Pure-read.

How do I install it?

Run `npx skills add ruvnet/ruflo --skill harness-threat-model --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.

Where does this skill come from?

From ruvnet/ruflo, a repository with 67,015 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.

Is a popular skill a good skill?

Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.

Keep going