CtrlK
BlogDocsLog inGet started
Tessl Logo

configure-secret-scan

Add secret detection scanning steps to existing Harness pipelines using STO security scanners. Detects exposed credentials, API keys, tokens, and sensitive data in code repositories. Supports Harness Code (default, native, unified SAST/SCA/secret detection), Gitleaks (standalone secret scanner, open-source), Semgrep, Snyk, SonarQube, Checkmarx, Fossa, Aqua Trivy, and Wiz. Only works with existing pipelines that have a codebase connector configured. Use when asked to add secret scanning, detect exposed secrets, find leaked API keys, configure secret detection, or scan code for credentials. Trigger phrases: add secret scan, detect secrets, find leaked credentials, configure secret detection, scan for exposed API keys, add Gitleaks, secret scanning pipeline.

72

Quality

88%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

76%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

Highly actionable content with concrete MCP calls and copy-paste YAML, clearly sequenced into eight steps. Its main gaps are the absence of an explicit validation/confirmation checkpoint before the destructive pipeline update and some redundancy between the Performance Notes and the step bodies.

Suggestions

Add an explicit validation/confirmation checkpoint before Step 7's harness_update — e.g., show the user the final YAML and confirm before applying, and/or validate the YAML parses — so destructive pipeline edits have a feedback loop.

Trim the 'Performance Notes' section, which duplicates rules already stated in the steps (default to Harness Code, place before build, cloneCodebase: true), or convert it into a short non-redundant quick-reference checklist.

Consider moving the full scanner auth-requirements table and per-scanner YAML templates into a one-level-deep reference file (e.g. references/scanners.md) so SKILL.md reads as a lean overview with clear navigation.

DimensionReasoningScore

Conciseness

Mostly efficient and free of concepts Claude already knows, but the 'Performance Notes' section restates rules already given in the steps (e.g., default to Harness Code, place before build, cloneCodebase requirement), which could be trimmed.

4 / 5

Actionability

Provides fully executable MCP tool-call parameter blocks and copy-paste-ready YAML step configs for each scanner, including exact auth field names and the <+secrets.getValue(...)> secret-reference format.

5 / 5

Workflow Clarity

The 8 steps are clearly sequenced, but modifying an existing pipeline via harness_update is a destructive/outward-facing operation with no explicit validation checkpoint or user-confirmation step before the update, so the cap at 3 applies.

3 / 5

Progressive Disclosure

Well-organized with clear section headers and no nested references, but it is a single ~275-line file with no bundle files; the scanner catalog and per-scanner YAML examples could be split into a one-level-deep reference file.

4 / 5

Total

16

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, concrete description that states capabilities in third person, enumerates supported scanners, and provides explicit 'Use when' guidance plus a trigger-phrase list. It clearly answers both what the skill does and when to invoke it.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'Add secret detection scanning steps to existing Harness pipelines', 'Detects exposed credentials, API keys, tokens, and sensitive data' — and enumerates the supported scanners comprehensively.

5 / 5

Completeness

Explicitly answers both what (add STO secret-detection steps to existing Harness pipelines) and when (concrete 'Use when...' trigger phrases), satisfying the top anchor.

5 / 5

Trigger Term Quality

Includes a dedicated 'Trigger phrases:' line plus a 'Use when asked to add secret scanning, detect exposed secrets, find leaked API keys...' clause covering natural synonyms users would actually say.

5 / 5

Distinctiveness Conflict Risk

Clear niche — secret detection in Harness pipelines via STO with a required codebase connector — with distinct triggers and minimal overlap with other skills.

5 / 5

Total

20

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
harness/harness-ai
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.