Skip to content

Latest commit

 

History

History
57 lines (38 loc) · 1.61 KB

File metadata and controls

57 lines (38 loc) · 1.61 KB

Harness SAST and SCA Skills

Agent skills for Qwiet AI by Harness cloud security workflows.

Release

v0.0.65

Install this release:

npx skills add ShiftLeftSecurity/skills@v0.0.65 --skill '*'

Track master for the latest build:

npx skills add ShiftLeftSecurity/skills --skill '*'

Then run:

/setup-harness-code-security-mcp
/run-security-scan
/triage-vuln
/autofix-vuln
/create-custom-policy
/deploy-custom-policy

Included Skills

  • setup-harness-code-security-mcp - install and verify the harness-code-security-mcp MCP launcher.
  • run-security-scan - run sl analyze or package CVE lookup.
  • triage-vuln - list findings and fetch data flows.
  • autofix-vuln - request and apply Qwiet AutoFix recommendations.
  • create-custom-policy - scaffold and validate custom .policy files.
  • deploy-custom-policy - validate a policy, ask before push, optionally set org/project assignment.

MCP Runtime

These skills expect the harness-code-security-mcp MCP server. The recommended npm runtime for this skills release is:

npm install -g harness-code-security-mcp@0.2.0

The setup skill can run a doctor helper and print host-specific MCP config snippets. The harness-code-security-mcp launcher checks for updates at startup and falls back to the installed server if the registry or network is unavailable.

Credentials

Run sl auth before scanning so ~/.shiftleft/config.json contains orgId and accessToken.

Source

Published from the Harness SAST and SCA release pipeline. Do not hand-edit this repository; contribute skill changes upstream instead.