Claude Skill MartBrowse skillsQuick linesLearn by videoTerminal guideWhat is a Skill?
← Back to list

Harness Audit (Four Rings)

A read-only audit of your agent's harness across four rings — containment, guides, sensors, permissions — that names the blast radius of the worst possible session.

Security & ReviewIntermediate★ 815⑂ 128AI score 8/10Last updated: Sep 29, 2026

What it does

Instead of reviewing your code, this skill reviews the environment your agent runs in, as four layers of defence:

  • Ring 1 — containment: what can the agent physically reach? Your checkout or a worktree/container, read-only DB user or the app's credentials, open internet or an allowlist, real API keys or test keys.
  • Ring 2 — guides: are CLAUDE.md / AGENTS.md and tool descriptions made of rules the agent can act on? It flags philosophy, history, anything over roughly a page, and missing rules for the repo's real landmines (migrations, generated files, deploy scripts).
  • Ring 3 — sensors: is there one command (make check or equivalent) running tests, linter and types, and does a hook run it automatically after edits? A check the model must remember to invoke is graded as a guide, not a sensor.
  • Ring 4 — permissions: what is auto-approved. Irreversible actions (push to main, deploy, spend, delete data, send messages) should require a human; reversible ones inside the walls should not. Approval fatigue counts as a hole, not a virtue.

Output is a one-sentence blast radius, held/open per ring, and a hardening list ranked outermost-first. The skill changes nothing.

Who it's for

  • Developers running coding agents against real repositories who want to know how bad a bad session could get
  • Teams whose repo holds production credentials, deploy scripts or migrations
  • Platform/DevOps folks standardising hooks and auto-approve lists

Examples

  1. "Is my Claude Code setup safe?" → ring-by-ring verdict plus a prioritised hardening list.
  2. "What could one bad session break?" → a blast-radius sentence derived from your actual credentials, permissions and sandboxing.
  3. "Review my AGENTS.md and hook guardrails" → flags unactionable prose, missing landmine rules, and checks that never run automatically.

· · · Install guide · · ·

Try it now, no install

Paste this into Claude to use the skill without installing anything.

Read the instructions in this file and follow them to help me:
https://raw.githubusercontent.com/undefined-ui/second-brain-os/HEAD/plugins/agents-course/skills/harness-audit/SKILL.md

What I want: (describe your task here)

If Claude can't open the link, open it yourself and paste the contents instead.

↓ If it works for you, download the ZIP below and install it. Then it runs on its own — no pasting each time.

Install in the Claude app (no terminal)
  1. Download the ZIP with the button below.
  2. In Claude, open Settings → Capabilities and turn on 'Code execution and file creation'. (one time)
  3. Go to Customize → Skills → + → 'Upload a skill' and upload the ZIP.
↓ Download ZIP
Install in Claude Code

Let Claude do it — paste this into Claude Code

Install the skill I found on Claude Skill Mart.
Copy the plugins/agents-course/skills/harness-audit folder from the GitHub repo undefined-ui/second-brain-os into my ~/.claude/skills/harness-audit/.
When it's done, tell me in one line what this skill can do.

Install with a command instead

git clone https://github.com/undefined-ui/second-brain-os.git /tmp/second-brain-os && mkdir -p ~/.claude/skills && cp -r /tmp/second-brain-os/plugins/agents-course/skills/harness-audit ~/.claude/skills/

⚠ This is a third-party skill. Check the source repository before installing.

  1. Open a terminal.
  2. Clone the repository: git clone https://github.com/undefined-ui/second-brain-os.git
  3. Create the skills directory: mkdir -p ~/.claude/skills
  4. Copy the skill: cp -r second-brain-os/plugins/agents-course/skills/harness-audit ~/.claude/skills/
  5. Verify that ~/.claude/skills/harness-audit/SKILL.md exists.
  6. Restart Claude Code and ask something like "audit my agent harness" or "review my sandboxing and permissions".
  7. Remember it is read-only: to apply the suggested hardening, start a separate editing session.