技能 编程开发 Harness MCP 静态安全扫描

Harness MCP 静态安全扫描

v20260927
harness-mcp-scan
该工具通过 harness mcp-scan 命令对声明的 MCP 表面进行静态安全扫描。它读取配置文件而不调用工具,标记策略、权限和依赖问题。当发现严重程度达到阈值时退出代码 1。支持 CI 集成,并在 harness 二进制文件不可用时优雅降级。
获取技能
311 次下载
概览

Calls harness mcp-scan to enumerate every declared MCP server + tool and flag policy / permission / dependency issues. Never executes any tool; pure static analysis.

Algorithm

Implementation: scripts/mcp-scan.mjs.

  1. Invoke the pinned harness binary (metaharness@~0.4.1, resolved from a local install or the one-time ~/.ruflo/metaharness-cache-<pin> cache — never @latest): harness mcp-scan <path> --json.
  2. Parse findings[] with { severity, id, server, tool, message }.
  3. --fail-on <severity>: exit 1 when any finding is at or above that level. Default high.
  4. Output JSON (default) or markdown table.

Severity rank

Severity Rank
low 1
medium 2
high 3

--fail-on high (default) only fails on HIGH; --fail-on medium also fails on MEDIUM; --fail-on low fails on any finding.

CI integration

- name: MCP static scan
  run: node plugins/ruflo-metaharness/scripts/mcp-scan.mjs --fail-on high

The exit code is the only thing CI watches; the JSON output goes to artifacts for human review.

Graceful degradation

When harness binary is unavailable (no network, blocked registry), emits structured { degraded: true, reason: 'metaharness-not-available' } and exits 0. Ruflo continues — ADR-150 architectural constraint.

信息
Category 编程开发
Name harness-mcp-scan
版本 v20260927
大小 1.68KB
更新时间 2026-09-28
语言