Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Static security scan of a harness's declared MCP surface via `harness mcp-scan <path>`. Reads `.mcp/servers.json` + `.harness/claims.json`. Pure-read, no dispatch. Exits 1 on findings at or above `--fail-on` severity.
| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-04 | ✗→✓ | ▲ Improved | -15% | 0% |
| case-05 | ✗→✓ | ▲ Improved | -27% | 0% |
| case-02 | ✗→✓ | ▲ Improved | 92% | 0% |
| case-01 | ✗→✓ | ▲ Improved | -12% | 0% |
| case-07 | ✗→✓ | ▲ Improved | -25% | 0% |
Calls harness mcp-scan to enumerate every declared MCP server + tool and flag policy / permission / dependency issues. Never executes any tool; pure static analysis.
Implementation: scripts/mcp-scan.mjs.
harness binary (metaharness@~0.3.0, resolved from alocal install or the one-time ~/.ruflo/metaharness-cache-<pin> cache — never @latest): harness mcp-scan <path> --json.
findings[] with { severity, id, server, tool, message }.--fail-on <severity>: exit 1 when any finding is at or above thatlevel. Default high.
| Severity | Rank | |---|---:| | low | 1 | | medium | 2 | | high | 3 |
--fail-on high (default) only fails on HIGH; --fail-on medium also fails on MEDIUM; --fail-on low fails on any finding.
yaml- name: MCP static scan run: node plugins/ruflo-metaharness/scripts/mcp-scan.mjs --fail-on high
The exit code is the only thing CI watches; the JSON output goes to artifacts for human review.
When harness binary is unavailable (no network, blocked registry), emits structured { degraded: true, reason: 'metaharness-not-available' } and exits 0. Ruflo continues — ADR-150 architectural constraint.
Other measured skills in the registry, with their headline benchmark lift.