create-secret — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited create-secret (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Generate Harness Secret definitions and manage secrets via MCP v2 tools.
| Tool | Resource Type | Purpose |
|---|---|---|
harness_list | secret | List existing secrets |
harness_get | secret | Get secret metadata (not the value) |
harness_create | secret | Create a new secret |
harness_update | secret | Update secret metadata or value |
harness_delete | secret | Delete a secret |
harness_describe | secret | Discover secret resource schema |
Stores text-based secrets: passwords, API tokens, connection strings.
secret:
identifier: my_api_key
name: My API Key
description: API key for external service
type: SecretText
spec:
secretManagerIdentifier: harnessSecretManager
valueType: Inline
value: <secret_value>For other secret types (SecretFile, SSHKey with KeyReference/KeyPath/Password, WinRmCredentials with NTLM/Kerberos) and secret manager configuration, consult references/secret-types.md.
| Scope | Visibility | MCP Parameters |
|---|---|---|
| Project | Only within the project | org_id + project_id |
| Organization | All projects in the org | org_id only |
| Account | All orgs and projects | Neither org_id nor project_id |
harness_list(
resource_type="secret",
org_id="<org>",
project_id="<project>",
search_term="<keyword>"
)harness_create(
resource_type="secret",
org_id="<org>",
project_id="<project>",
body={
"secret": {
"identifier": "my_api_key",
"name": "My API Key",
"type": "SecretText",
"spec": {
"secret_manager_identifier": "harnessSecretManager",
"value_type": "Inline",
"value": "<value>"
}
}
}
)harness_get(
resource_type="secret",
resource_id="my_api_key",
org_id="<org>",
project_id="<project>"
)# Project-level secret
<+secrets.getValue("my_api_key")>
# Org-level secret
<+secrets.getValue("org.my_api_key")>
# Account-level secret
<+secrets.getValue("account.my_api_key")>In connector configuration:
connector:
spec:
authentication:
spec:
tokenRef: github_pat # secret identifierIn service variables:
variables:
- name: DB_PASSWORD
type: Secret
value: <+secrets.getValue("db_password")>| Secret Type | Pattern | Example |
|---|---|---|
| API Keys | {service}_api_key | github_api_key |
| Passwords | {system}_password | prod_db_password |
| Tokens | {provider}_token | slack_token |
| SSH Keys | ssh_{purpose} | ssh_deploy_key |
| Certificates | {service}_cert | ssl_prod_cert |
Identifier must match: ^[a-zA-Z_][0-9a-zA-Z_]{0,127}$
/create-secret
Create a SecretText for a GitHub personal access token at the project level
using the Harness built-in secret manager/create-secret
Create an SSH key secret for deploying to production servers as the "deploy" user/create-secret
Create a secret that references the database password stored in HashiCorp Vault
at secret/data/production/database#password/create-secret
Show me all secrets in the payments project/create-secret
Create WinRM NTLM credentials for the Windows deployment servers| Error | Cause | Solution |
|---|---|---|
| Duplicate identifier | Secret with same ID exists | Use unique identifier or update existing |
| Secret manager not found | Invalid secretManagerIdentifier | Verify the secret manager connector exists |
| Encryption failed | Secret manager connectivity issue | Check delegate connectivity to secret manager |
| Invalid secret type | Unsupported type string | Use SecretText, SecretFile, SSHKey, or WinRmCredentials |
| Invalid valueType | Case mismatch | Use Inline or Reference (case-sensitive) |
org. prefix, account secrets need account. prefixcore_secret_view permissionharness_get on the connector)#key suffix for specific keyssecretsmanager:GetSecretValuecredentialType: Password first to isolate key-specific issues/audit-report skill~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.