CtrlK
BlogDocsLog inGet started
Tessl Logo

approve-exempt

Approve pending Harness STO security exemptions (waivers) at their current scope or elevate them to Project, Org, or Account scope. Users say "approve" for both in-scope approval and higher-scope elevation — do not require the word "promote". Supports approving one exemption or a mixed list where each row has a different approval scope. Default workflow lists pending exemptions in chat (paginated preview) so the user picks by row number — no copying from the Harness UI. Use when a user wants to approve, sign off on, or clear pending exemptions, waive approvals, org-wide approval, or account-wide approval. Trigger phrases: approve exempt, approve exemption, approve waiver, sign off exemption, clear pending exemption, approve for org, approve for account, org-wide approval, account-wide approval, pending exemptions.

72

Quality

88%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

77%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is highly actionable with concrete MCP call templates and a well-sequenced, validation-backed workflow for a batch approval operation. Its main weaknesses are redundancy (repeated list-first/zero-UI directives and overlapping scope tables) and a monolithic structure with no progressive disclosure despite the file's length.

Suggestions

Consolidate the repeated list-first / zero-UI-copy directive into one authoritative statement (e.g., in Step 2) and remove the duplicates from the intro, examples, performance notes, and troubleshooting to tighten conciseness.

Merge or cross-reference the 'Elevation paths' and 'Natural language → body.scope' tables, which cover the same CURRENT/PROJECT/ORG/ACCOUNT destinations from two angles, to remove overlapping content.

Move the 9 worked examples and/or the large troubleshooting table into reference files (e.g., references/examples.md, references/troubleshooting.md) with one-level-deep links from SKILL.md to improve progressive disclosure for this long skill.

DimensionReasoningScore

Conciseness

The body avoids explaining concepts Claude already knows, but it carries notable redundancy: the list-first/zero-UI directive is repeated across the intro, Step 2, Step 3, Examples, Performance Notes, and Troubleshooting, and the 'Elevation paths' table overlaps heavily with the 'Natural language → body.scope' table. This is 'mostly efficient but could be tightened' (anchor 3) rather than only minor trimming (anchor 4).

3 / 5

Actionability

Provides fully executable, copy-paste-ready MCP call templates for `harness_list` and `harness_execute` with exact field names (`body.scope`, `_action_id_by_row`, `_display_hint`, `_nextPageHint`), concrete per-row example inputs, and a confirmation-table template — covering the common cases as the anchor-5 example requires.

5 / 5

Workflow Clarity

A clear 7-step sequence includes an explicit validation checkpoint (Step 5 confirmation table plus 'Wait for explicit yes') and a feedback loop for batch failure ('If call 2 of 3 fails, report which succeeded and which failed — do not silently retry'), with an error-recovery troubleshooting table — matching the anchor-5 example with explicit validation and error-recovery loops for a high_write batch operation.

5 / 5

Progressive Disclosure

The skill is a single ~430-line monolithic SKILL.md with no bundle files and no external references; well-organized section headers exist, but content that clearly belongs in separate references (9 worked examples, the large troubleshooting table, the overlapping scope tables) is all inlined and loaded at once. This fits 'some structure but content that should be separate is inline' (anchor 3) better than the well-split anchor 4.

3 / 5

Total

16

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

This is a high-quality description that explicitly states capabilities, provides comprehensive natural trigger phrases, and clearly defines when to use the skill with minimal conflict risk. Its only weakness is mild verbosity — it interleaves workflow detail ('do not require the word promote', paginated-preview mechanics) that reads more like body guidance than a capability summary.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — approve at current scope, elevate to Project/Org/Account, list pending exemptions in chat with paginated preview, pick by row number, mixed-scope batches — giving comprehensive capability coverage. It is somewhat padded with workflow detail that belongs in the body, but the actions themselves are concrete and complete, matching the anchor-5 example.

5 / 5

Completeness

Clearly answers both 'what' (approve/elevate STO exemptions via a chat-based row-selection workflow) and 'when' ('Use when a user wants to approve, sign off on, or clear pending exemptions, waive approvals, org-wide approval, or account-wide approval') with concrete trigger phrases, exactly matching the anchor-5 example.

5 / 5

Trigger Term Quality

An explicit trigger-phrase list covers natural synonyms and variations a user would actually say — 'approve exempt', 'approve exemption', 'approve waiver', 'sign off exemption', 'clear pending exemption', 'approve for org', 'org-wide approval', 'account-wide approval', 'pending exemptions' — matching the comprehensive-synonyms anchor 5.

5 / 5

Distinctiveness Conflict Risk

Targets a clear niche (Harness STO security-exemption approval) with distinct, domain-specific triggers, so overlap with other skills is minimal — fitting the 'clear niche with distinct triggers; minimal conflict risk' anchor 5.

5 / 5

Total

20

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
harness/harness-ai
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.