harness-threat-model

v2026.09.24

Enterprise-review-grade threat model from `harness threat-model <path>`. Categorizes MCP-surface threats; emits `worst: 'clean'|'low'|'medium'|'high'` + per-threat findings. Pure-read.

GitHub
安装命令
npx skhub add ruvnet/harness-threat-model
Markdown
SKILL.md

The companion to harness-mcp-scan for enterprise security reviews. Where mcp-scan is a per-server static lint, threat-model produces a categorized report suitable for sharing with an InfoSec team.

Algorithm

Implementation: scripts/threat-model.mjs.

  1. Invoke the pinned harness binary (metaharness@~0.3.0, resolved from a local install or the one-time ~/.ruflo/metaharness-cache-<pin> cache — never @latest): harness threat-model <path> --json.
  2. Parse { worst, findings[] }.
  3. --fail-on <severity>: exit 1 when worst >= fail-on. Default high.

Severity rank

SeverityRank
clean0
low1
medium2
high3

When to use

  • Pre-launch review: include the JSON output in the release-readiness packet sent to security.
  • Periodic audit: schedule via the planned oia-audit background worker (ADR-150 Phase 2) to detect MCP-surface drift.

Graceful degradation

Same pattern as the other skills: when harness is absent, emit { degraded: true } and exit 0. ADR-150 architectural constraint.

发现
标签

此技能尚未发布标签。

版本
最新版本元数据

版本

v2026.09.24

发布时间

2026年9月24日

分类

未分类

许可证

MIT

源路径

plugins/ruflo-metaharness/skills/harness-threat-model

默认分支

main

最新提交

0a96fb8

Tree SHA

f154406