CtrlK
BlogDocsLog inGet started
Tessl Logo

generate-slsa

Add a SLSA Generation step (YAML type: provenance) to an existing Harness pipeline to generate SLSA provenance and optionally attest with Cosign (keyless, key-based, or Vault). Supports container images (Docker, ECR, GCR, GAR, ACR, HAR) and Harness Local Stage artifacts. Place after image build/push; run sequentially after SBOM steps, not in parallel. Only works with existing pipelines. Use when asked to generate SLSA, add SLSA provenance, SLSA Generation step, attest SLSA, or configure SLSA Level 3 provenance in a pipeline. Trigger phrases: generate SLSA, SLSA generation, add SLSA step, SLSA provenance, attest SLSA, SlsaGeneration, provenance step, SLSA attestation, add provenance step.

75

Quality

94%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

88%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-engineered skill body: an explicitly sequenced wizard with confirmation gates and validation-error retry, concrete YAML/MCP examples, and genuine one-level-deep reference files. The main improvements are deduplicating rules stated three to four times and moving the summary template and troubleshooting detail into reference files to slim the core SKILL.md.

Suggestions

State each global rule once (in the Interaction model) and reference it elsewhere; 'sequential with SBOM' and 'do not execute the pipeline' are each repeated 3-4 times across sections.

Move the full 'Provide summary' output template into a reference file (or the wizard-flow reference) and keep only the required fields inline.

Trim the Troubleshooting section to the highest-frequency failure modes inline and delegate the rest to a references/troubleshooting.md file.

DimensionReasoningScore

Conciseness

The body is dense and efficient — tables, terse bullets, and concrete YAML with no explanation of concepts Claude already knows. However, several rules are repeated three to four times (SBOM sequencing appears in the interaction model, insertion rules, Performance Notes, and Troubleshooting; 'do not execute the pipeline' likewise recurs four times), so not quite 'every token earns its place' (5) — it sits at the 4 anchor ('efficient; minor instances that could be trimmed').

4 / 5

Actionability

Guidance is fully executable: copy-paste-ready YAML for the step (with real values like `lavakush07/easy-buggy-app:blog`), concrete MCP invocations with parameters (`harness_update` with resource_type/org_id/project_id/body), a phase-by-phase table, and troubleshooting entries pairing symptoms with fixes. Matches the 5 anchor ('fully executable; copy-paste ready; specific examples cover the common cases').

5 / 5

Workflow Clarity

The 10-phase wizard is explicitly sequenced with a breadcrumb, a 13-point mandatory interaction model acts as a checklist, and risky write operations are gated: 'Fetch before configure', 'Confirm before write', and an explicit error-recovery loop ('On validation errors, read the API message, fix fields... retry'). This matches the 5 anchor's validation steps, feedback loops, and checklists.

5 / 5

Progressive Disclosure

Structure is good and references are real, clearly signaled, and one level deep (interactive-wizard-flow.md, slsa-generation-step.md, cd-containerized-step-group.md), with bulk detail (full phase prompts, per-registry specs, CD rules) correctly delegated. But the ~280-line body still inlines material that belongs in references — the entire output summary template and an extensive Troubleshooting section — fitting the 4 anchor ('most content appropriately placed; minor organization gaps') rather than the 5 anchor's lean overview.

4 / 5

Total

18

/

20

Passed

Description

96%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: concrete capabilities, explicit scope boundary ("Only works with existing pipelines"), and an explicit 'Use when' clause with comprehensive trigger phrases in third-person voice. The only weaknesses are minor trigger overlap with adjacent supply-chain skills and some redundancy between the 'Use when' sentence and the trailing trigger-phrase list.

Suggestions

Trim the duplicated trigger list: the 'Trigger phrases:' sentence repeats the 'Use when' clause almost verbatim; keep one.

Move placement detail ('Place after image build/push; run sequentially after SBOM steps, not in parallel') into the body — it is guidance for execution, not trigger-relevant capability description.

DimensionReasoningScore

Specificity

The description lists multiple concrete actions with comprehensive coverage: "Add a SLSA Generation step (YAML type: provenance) to an existing Harness pipeline to generate SLSA provenance and optionally attest with Cosign (keyless, key-based, or Vault)" plus enumerated supported sources (Docker, ECR, GCR, GAR, ACR, HAR, Harness Local Stage). This matches the 5 anchor ('multiple specific concrete actions; comprehensive coverage') and is well above the 4 anchor's 'minor gaps in coverage'.

5 / 5

Completeness

Both 'what' (add a provenance-type step to an existing Harness pipeline, generate SLSA provenance, optionally attest with Cosign) and 'when' are explicitly and concretely answered: "Use when asked to generate SLSA, add SLSA provenance, SLSA Generation step, attest SLSA, or configure SLSA Level 3 provenance in a pipeline" — a textbook match for the 5 anchor. Voice is third person, so no specificity penalty applies.

5 / 5

Trigger Term Quality

Trigger coverage is comprehensive with natural synonyms and variants: "generate SLSA, SLSA generation, add SLSA step, SLSA provenance, attest SLSA, SlsaGeneration, provenance step, SLSA attestation, add provenance step" — including both natural user phrasings and the API enum name. Matches the 5 anchor's 'comprehensive coverage of natural terms including synonyms'.

5 / 5

Distinctiveness Conflict Risk

The SLSA-provenance-generation niche is clear and triggers are generation-specific, but within the sibling Harness skill suite (e.g. /enforce-slsa verification, SBOM/SscaOrchestration, artifact signing), phrases like "attest SLSA" and "provenance step" carry minor overlap risk with closely related skills. This fits the 4 anchor ('mostly distinct; minor overlap risk with closely related skills') better than the 5 anchor's 'minimal conflict risk'.

4 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
harness/harness-ai
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.