harness-mint — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited harness-mint (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
The one write-capable skill in the plugin. Every other skill is pure-read. This one calls metaharness new, which writes a new directory tree.
--confirm, the script prints whatit would do and exits 0 without touching disk.
--target resolves to the currentworking directory OR any path inside it, the script errors out with exit 2. Target must be an absolute path OUTSIDE the calling repo (default is a fresh /tmp/ruflo-mint-<ts>-<name>/ dir).
non-existent dir.
execution. The mint stays sandboxed from ruflo's runtime.
Implementation: scripts/mint.mjs.
--name, --template. Default --host to claude-code.--target (default: temp dir).--confirm: emit dry-run plan, exit 0.--confirm: shell `npx metaharness new <name> --template <id>--host <id> --target <abs> --yes`.
minimal, vertical:coding, vertical:devops, vertical:support, vertical:legal, vertical:research, vertical:trading, vertical:health, vertical:education, vertical:sales, vertical:business, vertical:crm, vertical:marketing, vertical:advertising, vertical:ai, vertical:agentics, vertical:ruview, vertical:gaming, vertical:repo-maintainer, vertical:exotic.
claude-code, codex, pi-dev, hermes, openclaw, rvm, copilot, opencode, github-actions.
$ node scripts/mint.mjs --name my-harness --template vertical:coding --host claude-code
# harness-mint (dry-run)
- action: metaharness new
- name: my-harness
- template: vertical:coding
- host: claude-code
- target: /tmp/ruflo-mint-1718560000-my-harness
- confirm: false
- willWrite: false
Re-run with `--confirm` to actually scaffold.Ruflo's behavioral rules say "executing actions with care" — destructive or repo-touching actions need confirmation. The dry-run output makes the WHAT visible before the WHEN. A human sees target, decides, then adds --confirm if happy.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.