harness-mcp
Pass
Audited by Gen Agent Trust Hub on Aug 13, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill provides examples of using
npxto run the@anthropic-ai/mcp-harnessserver anddocker runcommands for deployment. These are documented as standard configuration steps for the MCP environment. - [EXTERNAL_DOWNLOADS]: The skill references standard, well-known resources from Harness and Anthropic (e.g.,
@anthropic-ai/mcp-harnessandharness/mcp-server:latest). These downloads are from trusted vendors and are necessary for the skill's primary purpose of CD automation. - [CREDENTIALS_SAFE]: The skill correctly instructs users to manage sensitive credentials (such as
HARNESS_API_KEYandjira_api_token) using environment variables or Harness's native secret management system rather than hardcoding them. - [DATA_EXFILTRATION]: While the skill contains code to interact with external APIs (Harness and Jira), these operations are consistent with its stated purpose of synchronizing development workflows and do not exhibit signs of unauthorized data exfiltration.
Audit Metadata