harness-security-reviewer

harness-security-reviewer is an agent for Claude Code from Intense-Visions/harness-engineering. It costs 17 tokens per session (13,412 once invoked), scanned A, a copy of harness-adversarial-reviewer, MIT.

A security-focused code-review agent that examines software for weaknesses using OWASP and CWE guidance. OWASP is a security organisation and CWE is a catalogue of common software weakness types.

In plain words
What is it for?
Auditing unfamiliar code, reviewing security-sensitive changes, checking dependency updates and reporting vulnerabilities with weakness references and remediation advice.
Why use it?
It helps find security problems before release, during sensitive code changes or after dependency updates.

Agent for Claude Code

Written for Claude Code: a Claude Code subagent (agents/*.md). Also seen: mentions CLAUDE.md; mentions subagents; names the AskUserQuestion tool.

Part of the harness-claude plugin — 85 skills, 89 commands, 16 agents, 4 hooks, 4 MCP servers shipped together

Good fit Auditing unfamiliar code, reviewing security-sensitive changes, checking dependency updates and reporting vulnerabilities with weakness references and remediation advice.

Compare 6 agents from other repositories ↓
Install with agentmods
npx agentmods add agents/intense-visions/harness-engineering/harness-security-reviewer
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Clone the repo
git clone --depth 1 https://github.com/Intense-Visions/harness-engineering

Made for: Claude Code.

Or install harness-claude, the plugin that ships this one along with the rest of its 85 skills, 89 commands, 16 agents, 4 hooks, 4 MCP servers.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for harness-security-reviewer

README.md
[![agentmods](https://agentmods.dev/badge/agents/intense-visions/harness-engineering/harness-security-reviewer/github.svg)](https://agentmods.dev/agents/intense-visions/harness-engineering/harness-security-reviewer)
Your own site
<a href="https://agentmods.dev/agents/intense-visions/harness-engineering/harness-security-reviewer"><img src="https://agentmods.dev/badge/agents/intense-visions/harness-engineering/harness-security-reviewer/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for harness-security-reviewer

Your own site · 80×15
<a href="https://agentmods.dev/agents/intense-visions/harness-engineering/harness-security-reviewer"><img src="https://agentmods.dev/badge/agents/intense-visions/harness-engineering/harness-security-reviewer.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 17 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 13,412 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin 92% copy Near-identical to another mod in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00017 $0.13412
Opus 5 $0.00009 $0.06706
Sonnet 5 $0.00003 $0.02682
Haiku 4.5 $0.00002 $0.01341

Measured 9d ago against content hash 35f108e3640f, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-08, from the pricing page.

Security

Grade A, and why

harness-security-reviewer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

Origin

This is a copy

92% identical to harness-adversarial-reviewer — 287 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.

.antigravity-extension/agents/harness-security-reviewer.md · 1,149 lines

How it starts

The opening of the file, as written. The whole thing — 1,149 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Role

Identifies security vulnerabilities, enforces secure coding patterns, and produces structured findings with CWE references and remediation guidance.

Skills

  • harness-security-review
  • harness-code-review

Steps

  1. Run harness validate (always)
  2. Run harness check-deps (always)
  3. Execute harness-security-review skill (on_pr)
  4. Execute harness-security-review skill (manual)

Methodology

Harness Security Review

Deep security audit combining mechanical scanning with AI-powered vulnerability analysis. OWASP baseline + stack-adaptive rules + optional threat modeling.

When to Use

  • Before a release or security-sensitive merge
  • After updating dependencies (supply chain risk)
  • When auditing a new or unfamiliar codebase
  • When on_pr triggers fire on security-sensitive paths
  • NOT for quick pre-commit checks (use harness-pre-commit-review for that)
  • NOT for general code review (use harness-code-review for that)

Scope Adaptation

This skill adapts its behavior based on invocation context — standalone or as part of the code review pipeline.

Detection

Check for pipelineContext in .harness/handoff.json. If present, run in changed-files mode. Otherwise, run in full mode.

# Check for pipeline context
cat .harness/handoff.json 2>/dev/null | grep -q '"pipelineContext"'

Changed-Files Mode (Code Review Pipeline)

When invoked from the code review pipeline (Phase 4 fan-out, security slot):

  • Phase 1 (SCAN): SKIPPED. The mechanical security scan already ran in code review Phase 2. Read the mechanical findings from PipelineContext.findings where domain === 'security' instead of re-running run_security_scan.
  • Phase 2 (REVIEW): Run OWASP baseline + stack-adaptive analysis on changed files only plus their direct imports (for data flow tracing). The changed file list is provided in the context bundle from the pipeline.
  • Phase 3 (THREAT-MODEL): SKIPPED unless --deep flag was passed through from code review.
  • Phase 4 (REPORT): SKIPPED. Return findings as ReviewFinding[] to the pipeline. The pipeline handles output formatting (Phase 7).

Read the full file on GitHub · 1,149 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 9d ago First seen · 1,149 lines · 17 tokens per session scan A 35f108e3640f

Subscribe to this mod's changes

harness-security-reviewer is an agent published in the GitHub repository Intense-Visions/harness-engineering (20 stars, last pushed today), licensed MIT. It adds 17 tokens to every session and 13,412 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. It is 92% identical to harness-adversarial-reviewer, differing in 287 lines, and is treated as a copy.

Related

Other agents, from other repositories

reviewer

Read-only reviewer for an SDD implementation — checks that the change satisfies the acceptance criteria it claims (stage 1) and meets quality/convention/edge-case bars (stage 2). Use after a task (or the whole feature) reaches GREEN, before it's considered done. It reads the diff and the upstream artifacts and reports…

genkovich/sdd · 81 tokens

atomic-auditor

Final gate for a finished implementation. Dispatched exactly once after the implement-review loop goes green, never per iteration. Never touches the repo; its one write is the audit report into the task scratchpad. Audits the delivered work as a whole: cumulative spec compliance, cross-iteration coherence…

damusix/atomic-claude · 169 tokens

bt6-pr-auditor

Reviews one pull request in a BT6 codebase for correctness, research integrity, security, verification quality, and merge readiness.

elder-plinius/T3MP3ST · 32 tokens

Reviewer

Mandatory fast reviewer: validates every agent delegation output before acceptance. Checks acceptance criteria, file partitions, regressions, type safety, security basics.

monkilabs/opencastle · 30 tokens

security-auditor

Use this agent when reviewing local code changes or pull requests to identify security vulnerabilities and risks. This agent should be invoked proactively after completing security-sensitive changes or before merging any PR.

NeoLabHQ/context-engineering-kit · 40 tokens

reviewer-architecture

Use this agent for architecture-focused code review. Evaluates implementation against the plan's architectural decisions, checks separation of concerns, pattern consistency, and proper use of existing abstractions. Spawned in parallel with other reviewers when a review task is dispatched.

HirogaKatageri/hirokata · 56 tokens