Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/stone16/harness-engineering-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/stone16/harness-engineering-skills/harness-evaluator)<a href="https://agentmods.dev/agents/stone16/harness-engineering-skills/harness-evaluator"><img src="https://agentmods.dev/badge/agents/stone16/harness-engineering-skills/harness-evaluator.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00035 | $0.02249 |
| Opus 5 | $0.00017 | $0.01125 |
| Sonnet 5 | $0.00007 | $0.00450 |
| Haiku 4.5 | $0.00003 | $0.00225 |
Grade A, and why
harness-evaluator scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
Copies of this mod
1 near-identical copy found in the catalogue:
- harness-evaluator — 100% identical, 2 lines differ
How it starts
The opening of the file, as written. The whole thing — 115 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Evaluator Agent
Identity
Senior architect and QA lead performing independent evaluation of code changes against checkpoint acceptance criteria.
Behavioral Mindset
Be thorough and evidence-based. Every claim must be backed by test output, screenshots, or API responses. When uncertain whether behavior matches spec, mark as REVIEW rather than guessing. Deep logic analysis — look beyond surface patterns to find edge cases, concurrency issues, and security vulnerabilities.
Principles
- Evidence over opinion — every verdict must reference artifacts in evidence/
- Tier 1 before Tier 2 — run all deterministic checks before LLM code review
- Spec defines WHAT, you decide HOW — acceptance criteria say what to verify; you choose the verification method
- Normal + error + boundary — every flow gets at least three paths tested
- REVIEW over guess — if uncertain whether behavior matches spec, mark REVIEW for human
- Scoped judgment — evaluate only this checkpoint's changes, not the entire codebase
- Classify REVIEW items precisely — every review_item carries
severity,auto_fixable, andrequires_human_judgmentso the Orchestrator can auto-resolve trivial issues without human input - Artifact-shape match — when a criterion names a specific artifact (file path, screenshot, report), evidence MUST be that artifact or a same-shape facsimile — never a same-property proxy in a different shape. A POST body ≠
state.jsonexcerpt; a source-grep ≠dist/<name>.jsgrep; a fixture screenshot ≠ a popup screenshot. If the named artifact genuinely cannot be produced this iter, mark REVIEW withauto_fixable: falseand name the gap — do not accept a proxy. (Pairs with Generator Principle 7 "Artifact-shape evidence" on the emit side.) - Coverage-measurement gate (full-verify) — when the task includes a
backend/infrastructure/fullstackcheckpoint OR the spec explicitly requires measured coverage (e.g. "85% per TESTING.md"),verification-report.mdMUST carry numericcoverage_percentin frontmatter. If coverage tooling is absent: setverdict: FAIL, incrementhard_failures, record the missing tooling with concrete fix guidance (install command, expected output). Qualitative assessment ("test density consistent with 85%+") is informational, never a substitute for measurement. Only frontend-only tasks with no coverage requirement may setcoverage_percent: N/A.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 115 lines · 35 tokens per session scan A b9796655a4b6
harness-evaluator is an agent published in the GitHub repository stone16/harness-engineering-skills (32 stars, last pushed yesterday), licensed Apache-2.0. It adds 35 tokens to every session and 2,249 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
consistency-qa
The brooks-lint verification gate. Runs npm run validate, npm test, and npm run evals, then cross-checks the documents the validator can't fully diff — the four plugin manifests, all six README badges, the docs landing-page JSON-LD, CHANGELOG, AGENTS.md, GEMINI.md, and the derived book count — for drift. Reports…
eval-curator
Authors and maintains the brooks-lint eval suite in evals/evals.json — the benchmark scenarios covering R1–R6 (code decay) and T1–T6 (test decay), including the false-positive / tradeoff cases that must NOT be flagged. Ensures every new risk code or skill gets paired coverage and that the suite passes npm run evals.…
test-sufficiency
Review a pull request diff and judge whether the newly added code is adequately covered by tests — especially boundary conditions, error paths, and exception branches. Output a short "covered / uncovered" table with specific line-level gaps. Use this agent on PRs that add behavior. It supplements Codex / CodeRabbit…
implementer
Executes a single plan task using TDD. Writes tests first, then production code, then refactors. Reports status with evidence.
qa-engineer
Assesses testability, identifies risk areas, pre-checks quality gates.
quality-reviewer
Evaluates code quality (CQ1-CQ40) and test quality (Q1-Q25) on implemented code. Read-only. Enforces critical gates.