CtrlK
BlogDocsLog inGet started
Tessl Logo

configure-repo-scan

Configure code scanning in Harness pipelines using STO security scanners. Helps identify where to inject SAST/SCA scanning steps into existing pipelines, recommends appropriate scanners, and configures them with proper connector references. Use when asked to add code scanning, configure security scans, set up SAST/SCA, integrate vulnerability scanning, or add security checks to a pipeline. Trigger phrases: add code scanner, configure repo scan, set up SAST, add security scan, configure vulnerability scanning, integrate scanner.

74

Quality

91%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is highly actionable with concrete MCP calls and copy-paste YAML, a clear 8-step workflow, and proper use of a one-level-deep reference. The main weaknesses are mild redundancy in the Performance Notes section and the absence of an explicit pre-update validation checkpoint in the main flow.

Suggestions

Collapse or remove the 'Performance Notes' section — its bullets duplicate rules already stated in Steps 2, 4, 5, and 6 (verify pipeline exists, extract connector automatically, use native STO steps, default to Harness Code).

Add an explicit validation checkpoint before Step 7 (e.g., 'Validate the updated YAML: correct 2-space indentation, identifier matches ^[a-zA-Z_][0-9a-zA-Z_]{0,127}$, step is in a CI stage') and only call harness_update when it passes, turning the Troubleshooting guidance into a pre-flight gate.

Move the full 'Available SAST Scanners' list into references/scanner-types.md and keep only Harness Code, Bandit, and Semgrep inline with the others summarized as 'See references/scanner-types.md' to tighten the overview.

DimensionReasoningScore

Conciseness

Mostly efficient with no over-explanation of concepts Claude already knows, but the 'Performance Notes' section restates guidance already covered in the steps (verify pipeline exists, extract connector, use native STO steps) and could be trimmed.

4 / 5

Actionability

Fully executable guidance: copy-paste MCP tool calls with named parameters, ready-to-use YAML step configs for the three common scanners, explicit insertion rules, and a concrete pipeline-studio URL template.

5 / 5

Workflow Clarity

Eight clearly sequenced steps with a guard in Step 2 and an error-recovery Troubleshooting section, but the main flow lacks an inline 'validate YAML before calling harness_update' checkpoint for this pipeline-modifying operation — a minor validation gap rather than a missing one.

4 / 5

Progressive Disclosure

A well-signaled one-level-deep reference (references/scanner-types.md, verified present) defers scanner-specific configs while three common scanners stay inline; the body is slightly long with the full scanner list and Performance Notes that could be further split out.

4 / 5

Total

17

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is exemplary: it states concrete capabilities, provides comprehensive natural trigger terms, explicitly covers both what and when, and occupies a distinct niche. Third-person voice is maintained throughout with no first/second-person slips.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'identify where to inject SAST/SCA scanning steps', 'recommends appropriate scanners', 'configures them with proper connector references' — giving comprehensive coverage of the skill's capabilities.

5 / 5

Completeness

Explicitly answers both what ('Configure code scanning... recommends... configures') and when ('Use when asked to add code scanning, configure security scans...') with concrete trigger phrases.

5 / 5

Trigger Term Quality

Comprehensive natural trigger terms with synonyms — 'add code scanning, configure security scans, set up SAST/SCA, integrate vulnerability scanning' plus an explicit 'Trigger phrases' list users would naturally say.

5 / 5

Distinctiveness Conflict Risk

A clear niche — Harness pipelines + STO security scanners + SAST/SCA — with distinct triggers and minimal overlap risk with other skills.

5 / 5

Total

20

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
harness/harness-ai
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.