CtrlK
BlogDocsLog inGet started
Tessl Logo

enforce-slsa

Add an SLSA Verification (SlsaVerification) step to an existing Harness pipeline to verify SLSA provenance attestations and optionally enforce OPA policy sets on provenance data. Supports CI and CD (Deployment) including CI-only pipelines — append a Deploy stage via Phase 3b when verifying before deploy. Supports Docker, ECR, GCR, GAR, ACR, HAR, and Local artifacts. Only works with existing pipelines. Use when asked to verify SLSA, enforce SLSA policies, add SLSA verification step, validate SLSA attestation, or gate deploy on SLSA provenance. Trigger phrases: enforce SLSA, SLSA verification, verify SLSA, SLSA policy enforcement, SlsaVerification, verify SLSA attestation, add SLSA verify step.

76

Quality

95%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

88%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A strong, highly actionable skill body: complete wizard phases, executable YAML and MCP calls, and robust validation/error-recovery guidance. Its weaknesses are mild redundancy across Performance Notes and Troubleshooting and a cross-skill reference (the CD containerized step-group guide) that is repeated four times but not present in the bundle.

Suggestions

Remove duplication between Performance Notes and Troubleshooting (e.g., PascalCase source.type, image_path vs repo, and the CD containerized-group pointer each appear in both sections) — consolidate these into one canonical location and cross-reference it.

Fix the unresolved 'skills/generate-slsa/references/cd-containerized-step-group.md' reference: either ship a local copy under references/ (e.g., references/cd-containerized-step-group.md) or inline the essential stepGroup/stepGroupInfra YAML so the CD edge case is self-contained; cite it once instead of four times.

Trim the repeated 'do not execute the pipeline' guidance (stated in interaction model rule 10, the post-wizard section, Performance Notes, and the summary template) to a single explicit rule.

DimensionReasoningScore

Conciseness

The body is dense and telegraphic — tables, YAML snippets, and terse rules that assume Claude's competence (no SLSA concept explanations). However, several points are repeated nearly verbatim: 'skills/generate-slsa/references/cd-containerized-step-group.md' is cited four times (lines 39, 102, 259, 293), the do-not-execute rule appears three times, and the PascalCase source.type / image_path notes are duplicated between Performance Notes and Troubleshooting. This fits 'efficient; minor instances of over-explanation that could be trimmed' rather than score 5's 'every token earns its place'.

4 / 5

Actionability

Guidance is fully executable: copy-paste-ready YAML for keyless and keybased verify, policy enforcement, and step insertion; exact MCP invocations with parameters (harness_get/harness_update/harness_list with resource_type and body shape); a concrete field-mapping table (repo → image_path, lowercase → PascalCase); and specific error names with fixes (DUPLICATE_IDENTIFIER, CONNECTOR_NOT_FOUND). Not score 4: no gaps — even the API-rejects-flat fallback (nested cosign wrapper) is covered.

5 / 5

Workflow Clarity

The wizard is a clearly sequenced phase table (0–10 plus 3b) with breadcrumb labels, and the interaction model enforces explicit checkpoints: 'Fetch before configure' (harness_get before placement questions), 'Confirm before write' (summary + harness_update only after user confirms), and feedback loops for error recovery (validation-error retry with flat vs. nested cosign shapes, a full Troubleshooting section keyed to failure symptoms). This matches 'clear sequence with explicit validation steps; feedback loops for error recovery'.

5 / 5

Progressive Disclosure

Structure is good: an overview body with well-signaled one-level-deep references — 'references/interactive-wizard-flow.md' and 'references/slsa-verification-step.md' both exist in the bundle and hold the appropriate detail. However, 'skills/generate-slsa/references/cd-containerized-step-group.md' is referenced four times but does not exist in this bundle (no skills/ directory), making the key CD edge case depend on an unresolvable path. That unresolved navigation gap fits 'most content is appropriately placed; references mostly clear; minor organization gaps' rather than score 5's 'easy navigation'.

4 / 5

Total

18

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

An exemplary description: concrete actions, comprehensive scope and boundary statements, explicit 'Use when...' triggers with a supplementary trigger-phrase list, and a distinct verification niche clearly separated from the related generation and policy-authoring skills. Third-person imperative voice is used with no fluff or over-claims.

DimensionReasoningScore

Specificity

The description lists multiple concrete actions — 'Add an SLSA Verification (SlsaVerification) step', 'verify SLSA provenance attestations', 'optionally enforce OPA policy sets on provenance data' — plus comprehensive scope coverage: supported stages ('CI and CD (Deployment) including CI-only pipelines'), all seven artifact registries ('Docker, ECR, GCR, GAR, ACR, HAR, and Local'), and an explicit boundary ('Only works with existing pipelines'). This matches the anchor 'multiple specific concrete actions; comprehensive coverage'; it is not score 4 because there are no meaningful gaps in capability coverage.

5 / 5

Completeness

Both 'what' and 'when' are explicit: the what is stated in the first sentence ('Add an SLSA Verification step... to verify SLSA provenance attestations and optionally enforce OPA policy sets') and the when is a concrete 'Use when asked to verify SLSA, enforce SLSA policies, add SLSA verification step, validate SLSA attestation, or gate deploy on SLSA provenance' clause backed by a trigger-phrase list. This matches the anchor 5 example structure exactly; the score-4 anchor ('when could be more explicit') does not apply since triggers are enumerated.

5 / 5

Trigger Term Quality

Trigger terms are the natural phrases a user would say: 'verify SLSA', 'enforce SLSA', 'SLSA verification', 'validate SLSA attestation', 'gate deploy on SLSA provenance', 'add SLSA verify step', plus the technical term 'SlsaVerification'. Coverage includes verb variations (verify/validate/enforce) and an explicit 'Trigger phrases:' list; not score 4 because no common natural variant is missing.

5 / 5

Distinctiveness Conflict Risk

The description carves a clear niche (SLSA provenance verification within existing Harness pipelines) with verify-specific triggers that would not fire for sibling skills like /generate-slsa (generation) or /create-policy (policy authoring). Scope boundaries ('Only works with existing pipelines', verification vs. generation prerequisites) further reduce conflict risk, matching 'clear niche with distinct triggers; minimal conflict risk' rather than score 4, which requires a noted overlap risk with closely related skills.

5 / 5

Total

20

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
harness/harness-ai
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.