技能 编程开发 MCP 静态安全扫描工具

MCP 静态安全扫描工具

v20260707
harness-mcp-scan
本工具用于对Harness声明的MCP表面执行纯静态安全扫描。它通过读取配置文件(如servers.json和claims.json)来分析策略、权限和依赖关系问题,且不会执行任何底层工具。适用于CI/CD流程,用于强制执行安全策略和确保项目合规性。
获取技能
364 次下载
概览

Calls harness mcp-scan to enumerate every declared MCP server + tool and flag policy / permission / dependency issues. Never executes any tool; pure static analysis.

Algorithm

Implementation: scripts/mcp-scan.mjs.

  1. Invoke the pinned harness binary (metaharness@~0.3.0, resolved from a local install or the one-time ~/.ruflo/metaharness-cache-<pin> cache — never @latest): harness mcp-scan <path> --json.
  2. Parse findings[] with { severity, id, server, tool, message }.
  3. --fail-on <severity>: exit 1 when any finding is at or above that level. Default high.
  4. Output JSON (default) or markdown table.

Severity rank

Severity Rank
low 1
medium 2
high 3

--fail-on high (default) only fails on HIGH; --fail-on medium also fails on MEDIUM; --fail-on low fails on any finding.

CI integration

- name: MCP static scan
  run: node plugins/ruflo-metaharness/scripts/mcp-scan.mjs --fail-on high

The exit code is the only thing CI watches; the JSON output goes to artifacts for human review.

Graceful degradation

When harness binary is unavailable (no network, blocked registry), emits structured { degraded: true, reason: 'metaharness-not-available' } and exits 0. Ruflo continues — ADR-150 architectural constraint.

信息
Category 编程开发
Name harness-mcp-scan
版本 v20260707
大小 1.68KB
更新时间 2026-07-09
语言