harness-threat-model
Enterprise-review-grade threat model from `harness threat-model <path>`. Categorizes MCP-surface threats; emits `worst: 'clean'|'low'|'medium'|'high'` + per-threat findings. Pure-read.
npx skills add ruvnet/ruflo --skill harness-threat-model --agent claude-code
Same command for any agent — swap --agent for codex, cursor, copilot.
Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.
The companion to `harness-mcp-scan` for enterprise security reviews. Where mcp-scan is a per-server static lint, threat-model produces a categorized report suitable for sharing with an InfoSec team. ## Algorithm Implementation: [`scripts/threat-model.mjs`](../../scripts/threat-model.mjs). 1. Invoke the pinned `harness` binary (`metaharness@~0.3.0`, resolved from a local install or the one-time `~/.ruflo/metaharness-cache-<pin>` cache — never `@latest`): `harness threat-model <path> --json`. 2. Parse `{ worst, findings[] }`. 3. `--fail-on <severity>`: exit 1 when `worst >= fail-on`. Default `high`. ## Severity rank | Severity | Rank | |---|---:| | clean | 0 | | low | 1 | | medium | 2 | | high | 3 | ## When to use - Pre-launch review: include the JSON output in the release-readiness packet sent to security. - Periodic audit: schedule via the planned `oia-audit` background worker (ADR-150 Phase 2) to detect MCP-surface drift. ## Graceful degradation Same pattern as the other skills: when `harness` is absent, emit `{ degraded: true }` and exit 0. ADR-150 architectural constraint.
- Algorithm
- Severity rank
- When to use
- Graceful degradation
What does the harness-threat-model skill do?
Enterprise-review-grade threat model from `harness threat-model <path>`. Categorizes MCP-surface threats; emits `worst: 'clean'|'low'|'medium'|'high'` + per-threat findings. Pure-read.
How do I install it?
Run `npx skills add ruvnet/ruflo --skill harness-threat-model --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.
Where does this skill come from?
From ruvnet/ruflo, a repository with 67,015 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.
Is a popular skill a good skill?
Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.