H

harness-eval

Linter tool (static analysis rules) and LLM reviewer for AI agent harness files that runs quality and security health checks, catching cross-component security chains, redundancy, and config drift, and vets individual skills before install, across Claude Code, Cursor, Codex, Copilot, Gemini, and OpenCode

redhat-community-ai-tools/harness-eval · v8.0.0 · Development & Workflow

redhat-community-ai-toolsOwner verifiedcaution

Trust Score

60

Security

59

Surfaces

4

What is harness-eval?

harness-eval is a published development & workflow plugin for AI coding agents in the claude-code ecosystem, developed by redhat-community-ai-tools and distributed through the HOL AI plugin registry. Linter tool (static analysis rules) and LLM reviewer for AI agent harness files that runs quality and security health checks, catching cross-component security chains, redundancy, and config drift, and vets individual skills before install, across Claude Code, Cursor, Codex, Copilot, Gemini, and OpenCode

Canonical slug
redhat-community-ai-tools/harness-eval
Version
v8.0.0 · updated Oct 8, 2026

Trust & Reputation

HOL Trust Score
60

Factor Analysis

Per-metric points (0–100 each) combined via a weighted average into the overall score.

Installability
64pts
Maintenance
55pts
MCP Posture
100pts
Plugin Security
59pts
Provenance
70pts
Publisher Quality
75pts

Registry Snapshot

Publisher verification
No
Marketplace source
Unknown
Scanner
Broker fallback
Safety label
caution
Digest verified
Yes
4 bundled skills — copy or download SKILL.mdOpen skills

Trust & reputation

Trust & Reputation

HOL Trust Score
60

Factor Analysis

Per-metric points (0–100 each) combined via a weighted average into the overall score.

Installability
64pts
Maintenance
55pts
MCP Posture
100pts
Plugin Security
59pts
Provenance
70pts
Publisher Quality
75pts

Provenance

Plugin root
.
Source repo
https://github.com/redhat-community-ai-tools/harness-eval
Source commit
d20ee5fefbae…
Publisher verified
No
Owner verified
Manual review verified

Continuous scanner CI not detected

This plugin remains listed. Its overall trust score is reduced by 10% because security checks are not maintained in the source repository's CI.

Optional: maintain the scanner in the source repository's CI to receive the full trust score. Listing does not require that change.

Verified badge not detected

Add the HOL verified badge to the repository README to score +2% trust. Plugin owners can open that pull request from Guard Plugins.

Security Posture

caution
Safety label
59
Security score
0
High findings
Provider
registry-broker-fallback
Grade
F · caution
Version
Unknown
cisco-skill-scanner: unknown

Findings

mediumpublishabilitypublishability.link.missing.websiteURL

websiteURL should be present for marketplace readiness.

mediumpublishabilitypublishability.link.missing.privacyPolicyURL

privacyPolicyURL should be present for marketplace readiness.

mediumpublishabilitypublishability.link.missing.termsOfServiceURL

termsOfServiceURL should be present for marketplace readiness.

lowoperational-securitysupply-chain.lockfile-missing

Repository snapshot does not include a lockfile.

infoskill-securityskill-scan.unavailable

Cisco skill scanner timed out after 60000 ms

infoskill-securityskill-scan.unavailable

Cisco skill scanner timed out after 60000 ms

infoskill-securityskill-scan.unavailable

Cisco skill scanner timed out after 60000 ms

infoskill-securityskill-scan.unavailable

Cisco skill scanner timed out after 60000 ms

harness-eval — Frequently asked questions

What is harness-eval?
harness-eval is an AI plugin in the HOL registry. Linter tool (static analysis rules) and LLM reviewer for AI agent harness files that runs quality and security health checks, catching cross-component security chains, redundancy, and config drift, and vets individual skills before install, across Claude Code, Cursor,…
How do I install harness-eval?
Install harness-eval in your harness: Claude Code — /plugin marketplace add redhat-community-ai-tools/harness-eval; Cursor — npx skills add redhat-community-ai-tools/harness-eval; Antigravity CLI — npx skills add redhat-community-ai-tools/harness-eval. Full step-by-step guidance is on the HOL plugin page.
How do I install harness-eval in Claude Code?
To install harness-eval in Claude Code, start with /plugin marketplace add redhat-community-ai-tools/harness-eval. The complete step-by-step install guide for Claude Code is on the HOL plugin page.
How do I install harness-eval in Cursor?
To install harness-eval in Cursor, start with npx skills add redhat-community-ai-tools/harness-eval. The complete step-by-step install guide for Cursor is on the HOL plugin page.
How do I install harness-eval in Antigravity CLI?
To install harness-eval in Antigravity CLI, start with npx skills add redhat-community-ai-tools/harness-eval. The complete step-by-step install guide for Antigravity CLI is on the HOL plugin page.
Is harness-eval free?
Pricing for harness-eval is published on its HOL plugin page when the maker schedules a launch.
Who publishes harness-eval?
harness-eval is published by redhat-community-ai-tools and listed on HOL.
Is harness-eval available now?
harness-eval availability is listed on its HOL plugin page.

Install Guidance

Install in Claude Code

Install through the Claude Code plugin marketplace.

Claude Code plugin docs
  1. 1

    Add the marketplace

    Run this inside a Claude Code session.

    claude code
  2. 2

    Install the plugin

    Use the plugin name and the marketplace name shown by the previous command.

    claude code
  3. 3

    Scripted alternative

    Non-interactive equivalent for scripts and CI pipelines. Add --scope project to pin the install to one repository.

    shell

Plugin Manifest

{
  "name": "harness-eval",
  "displayName": "Setup Eval",
  "version": "8.0.0",
  "description": "Evaluate AI agent setups for best practices, redundancy, security, and cross-component issues.",
  "author": {
    "name": "Benjamin Kapner"
  },
  "repository": "https://github.com/redhat-community-ai-tools/harness-eval",
  "license": "Apache-2.0",
  "keywords": [
    "evaluation",
    "harness",
    "setup",
    "skills",
    "configuration",
    "security"
  ],
  "interface": {
    "displayName": "Setup Eval",
    "developerName": "redhat-community-ai-tools"
  },
  "skills": "./",
  "holManifestOrigin": "repository",
  "registryIndexVersion": 5
}

Marketplace Source

Repo URL
https://github.com/redhat-community-ai-tools/harness-eval
Marketplace path
Unknown
Source path
.
Install policy
Unspecified

Skills

4 SKILL.md files ship with this plugin. Preview, copy, or download each one, then install them with the Skills CLI.

Share
skills-cli
  • autonomy

    skills/autonomy/SKILL.md

    Run the decidable checks an auto-merge policy can trust on the agent setup (harness-eval harness-autonomy). Block and policy rules only, no heuristics, no LLM. Exit 0 PASS, 1 FAIL, 2 REVIEW_REQUIRED. Use when the user asks whether a configuration change is safe to merge without a human, or wants the evidence block for a merge decision.

    Raw SKILL.md
  • lint

    skills/lint/SKILL.md

    Run the quality lint on the full agent setup (instruction files, skills, commands, hooks, agents, settings, MCP configs, harnesses). Advice rules plus system-level analysis by default; add --all for every one of the 92 rules. No LLM. Use when the user wants a fast structural health report. For a merge gate use /autonomy; for security use /security.

    Raw SKILL.md
  • review

    skills/review/SKILL.md

    Full qualitative review of the agent setup. Reads every file, applies per-component rubrics, runs 21 cross-type optimization checks, and produces KEEP/REVIEW/REMOVE verdicts. Use when the user wants a deep review, redundancy check, or quality assessment of their setup.

    Raw SKILL.md
  • security

    skills/security/SKILL.md

    Security audit of the agent setup. Every policy and heuristic (signal) rule plus the security-category block rules (prompt injection, credential access, exfiltration, obfuscation, taint tracking, permission grants, MCP secrets and endpoints, YARA, CVE lookup), then LLM semantic review. Heuristic findings are claims to read, not verdicts. Use when the user asks about security or needs a pre-deployment audit.

    Raw SKILL.md

File Inventory

.claude-plugin/plugin.json

file

439 bytes

59c41dbf313182ec…

.codex-plugin/plugin.json

plugin-manifest

548 bytes

a5fc6ff5e04ae018…

CLAUDE.md

file

4,562 bytes

bae7af2941b2a80f…

commands/harness-autonomy.md

file

511 bytes

3d3ed12165cd3f75…

commands/harness-gate.md

file

532 bytes

fdde40caa1de0395…

commands/harness-lint.md

file

516 bytes

75c6fa508a81260b…

commands/harness-review.md

file

533 bytes

b874e8bcf876ebd8…

commands/harness-security.md

file

468 bytes

a9f6888d37fa10e6…

README.md

file

13,312 bytes

1f9d0e1ccfbcd858…

SECURITY.md

file

2,733 bytes

7df4add2bfb87785…

skills/autonomy/SKILL.md

skill

2,606 bytes

1f664758d2159bc1…

skills/lint/report-format.md

skill

2,926 bytes

9b011dbcac894e55…

skills/lint/SKILL.md

skill

2,726 bytes

5b6b06e405ae8cb7…

skills/review/report-format.md

skill

3,154 bytes

eefeeda48e41d6db…

skills/review/rubric/agents-rubric.md

skill

3,497 bytes

9e4276b651bcb4ba…

skills/review/rubric/claude-md-rubric.md

skill

4,736 bytes

a081b80503d86e8e…

skills/review/rubric/commands-rubric.md

skill

3,500 bytes

d0447fcde1b9dbef…

skills/review/rubric/cross-type-checks.md

skill

7,193 bytes

460c14244978dceb…

skills/review/rubric/hooks-rubric.md

skill

2,826 bytes

4dca3a96047a5b09…

skills/review/rubric/skills-rubric.md

skill

9,541 bytes

8f6bbc17d68bbdef…

skills/review/SKILL.md

skill

4,297 bytes

404dc769d09a6a84…

skills/security/report-format.md

skill

2,815 bytes

a51fed75075c14fc…

skills/security/rubric/security-review-rubric.md

skill

3,897 bytes

f6604d1c69205b4e…

skills/security/SKILL.md

skill

3,265 bytes

2fa21e63be941a9f…