本文へ移動
cccskills
無料GitHub で公開

harness-audit

Audit an agent's harness against the four rings: containment, guides, sensors, permissions. Use when the user asks whether their agent setup is safe, wants a review of sandboxing / permissions / hooks / AGENTS.md guardrails, or asks what a bad session could break. Read-only: reports the blast radius and a hardening list, changes nothing. Do NOT use for context layout (context-audit) or cost routing (gate-check).

インストール方法を見る

含まれるファイル(1)

  • SKILL.md3.4 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Audit the four rings

Theory: The four rings and Harness practice. Build from the outside in: containment, guides, sensors, permissions. The order matters because each ring must hold when every ring inside it fails — a guide can be ignored, a sensor can miss, an approval can be misclicked; a wall does not care.

Core rule

Report and rank; never harden anything yourself. The audit's one organising question is the blast radius: describe the worst session possible under the current setup and what it costs. If the user asks you to apply fixes afterwards, that is a normal edit session, not this skill.

Workflow

  1. Ring one — containment: what can it physically reach? Where does the agent run: the user's checkout or a worktree/container? Which credentials are in its environment — a read-only database user or the application's? Open internet or an allowlist? Real API keys or test keys? The finding is one sentence: "the worst session deletes X and spends Y."
  2. Ring two — guides: what does it read before acting? Find CLAUDE.md / AGENTS.md and tool descriptions. Every line should be a rule the agent can act on — flag philosophy, history, and anything over roughly a page. Flag missing rules for the repo's real landmines (migrations, generated files, deploy scripts).
  3. Ring three — sensors: what fires when it errs? Is there one command (make check or equivalent) that runs tests, linter and types? Does the harness run it automatically after edits — a hook — or does correctness depend on the model remembering? A sensor the model must invoke voluntarily is a guide, not a sensor.
  4. Ring four — permissions: what still needs a human? List what is auto-approved. The irreversible set — push to main, deploy, spend, delete data, send messages — should need a person; everything reversible inside the walls should not. Flag both failure modes: irreversible actions auto-approved, and reversible ones prompting so often the user rubber-stamps (approval fatigue is a hole in this ring, not a virtue).
  5. Check the order. The classic smell is an inner ring doing an outer ring's job: a prompt line saying "never touch prod" where a credential should have been removed. Rules in guides that could be walls belong in ring one.

Output format

Harness audit — <project>
blast radius: <the worst session in one sentence>

ring 1 containment  <held | open>  <finding>
ring 2 guides       <held | open>  <finding>
ring 3 sensors      <held | open>  <finding>
ring 4 permissions  <held | open>  <finding>

Hardening list, outermost first:
1. ...

Rank fixes outside-in — a wall before a better prompt, a sensor before a politer rule. Close by restating the blast radius as it would be after fix 1 alone.

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Audit an agent's context layout against the four places: system prompt, tools, history, tail. Use when the user asks to audit, review or fix their agent's context, prompt caching, token spend per turn, or CLAUDE.md / AGENTS.md layout. Read-only: reports findings and a fix list, changes nothing. Do NOT use for writing evals (evals-bootstrap) or for loop design (goal-test).

日本語の概要は準備中です。原文の説明を表示しています。

undefined-ui/second-brain-os1,0222026年10月10日 更新

Scaffold a first eval suite for an agent: mine real failures into cases, write behavioural checks over traces, and generate the runner. Use when the user wants evals, regression tests for an agent, a golden set, or asks how to know a prompt/model change did not break things. Do NOT use for a single task's done-check (goal-test) or for auditing context (context-audit).

日本語の概要は準備中です。原文の説明を表示しています。

undefined-ui/second-brain-os1,0222026年10月10日 更新

Find the decisions in a pipeline that do not need the expensive model and propose the gate for each: a rule, a classic classifier, or a small model, with fail-closed routing. Use when the user asks to cut model costs or latency, says the big model handles everything, or wants a triage / routing / filter layer in front of an agent. Analysis plus an optional baseline scaffold. Do NOT use for auditing context layout (context-audit) or for building eval suites (evals-bootstrap).

日本語の概要は準備中です。原文の説明を表示しています。

undefined-ui/second-brain-os1,0222026年10月10日 更新

goal-test

無料

Turn a vague task into a testable definition of done and generate an executable goal-test script for it, optionally with a bounded retry loop around a headless agent. Use when the user wants to run an agent in a loop, asks how to know when an agent task is finished, or says a goal like "improve X" needs to become checkable. Do NOT use for building eval suites over many cases — that is evals-bootstrap.

日本語の概要は準備中です。原文の説明を表示しています。

undefined-ui/second-brain-os1,0222026年10月10日 更新

Import a large archive into the vault in controlled batches: triage what is worth ingesting, process oldest first, checkpoint after every batch, and keep cost visible. Use this skill whenever the user wants to import years of bookmarks, an export from another notes app, a downloads folder, a chat history dump, or says "backfill", "bulk import", "process my archive". Do NOT use for ingesting one or a few new sources, which is second-brain-ingest.

日本語の概要は準備中です。原文の説明を表示しています。

undefined-ui/second-brain-os1,0222026年10月10日 更新

Trace where the user's recorded position on something has shifted: superseded claims, contradictions between sources of different dates, and what evidence moved them. Use this skill when the user asks what they have changed their mind about, how their thinking on a topic developed, what they used to believe, or wants a quarterly look back at their own positions. Do NOT use for finding contradictions between sources with no time dimension, or for a current-state answer.

日本語の概要は準備中です。原文の説明を表示しています。

undefined-ui/second-brain-os1,0222026年10月10日 更新

undefined-ui のスキルをすべて見る

このスキルの問題を報告する