harness-evaluator

harness-evaluator is an agent for Claude Code from stone16/harness-engineering-skills. It costs 35 tokens per session (2,249 once invoked), scanned A, original, Apache-2.0.

An independent code-review agent that checks whether a change meets stated acceptance criteria using tests and other evidence.

In plain words
What is it for?
Use it to evaluate a checkpoint in a development workflow. It runs fixed checks first, then performs deeper logic analysis and marks uncertain findings for human review.
Why use it?
It helps catch missed requirements, edge cases, concurrency problems, and security issues before a change is accepted.

Agent for Claude Code

Written for Claude Code: shipped in a Claude Code plugin. Also seen: model in frontmatter; mentions Codex; built for gstack.

Part of the harness-engineering-skills plugin — 2 skills, 5 agents shipped together

Good fit Use it to evaluate a checkpoint in a development workflow. It runs fixed checks first, then performs deeper logic analysis and marks uncertain findings for human review.

Compare 6 agents from other repositories ↓
Install with agentmods
npx agentmods add agents/stone16/harness-engineering-skills/harness-evaluator
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Clone the repo
git clone --depth 1 https://github.com/stone16/harness-engineering-skills

Made for: Claude Code.

Or install harness-engineering-skills, the plugin that ships this one along with the rest of its 2 skills, 5 agents.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for harness-evaluator

README.md
[![agentmods](https://agentmods.dev/badge/agents/stone16/harness-engineering-skills/harness-evaluator.svg)](https://agentmods.dev/agents/stone16/harness-engineering-skills/harness-evaluator)
Your own site
<a href="https://agentmods.dev/agents/stone16/harness-engineering-skills/harness-evaluator"><img src="https://agentmods.dev/badge/agents/stone16/harness-engineering-skills/harness-evaluator.svg" alt="Measured on agentmods" height="20"></a>
Per session 35 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 2,249 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00035 $0.02249
Opus 5 $0.00017 $0.01125
Sonnet 5 $0.00007 $0.00450
Haiku 4.5 $0.00003 $0.00225

Measured 8d ago against content hash b9796655a4b6, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-08, from the pricing page.

Security

Grade A, and why

harness-evaluator scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

Origin

Copies of this mod

1 near-identical copy found in the catalogue:

plugins/harness-engineering-skills/agents/harness-evaluator.md · 115 lines

How it starts

The opening of the file, as written. The whole thing — 115 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Evaluator Agent

Identity

Senior architect and QA lead performing independent evaluation of code changes against checkpoint acceptance criteria.

Behavioral Mindset

Be thorough and evidence-based. Every claim must be backed by test output, screenshots, or API responses. When uncertain whether behavior matches spec, mark as REVIEW rather than guessing. Deep logic analysis — look beyond surface patterns to find edge cases, concurrency issues, and security vulnerabilities.

Principles

  1. Evidence over opinion — every verdict must reference artifacts in evidence/
  2. Tier 1 before Tier 2 — run all deterministic checks before LLM code review
  3. Spec defines WHAT, you decide HOW — acceptance criteria say what to verify; you choose the verification method
  4. Normal + error + boundary — every flow gets at least three paths tested
  5. REVIEW over guess — if uncertain whether behavior matches spec, mark REVIEW for human
  6. Scoped judgment — evaluate only this checkpoint's changes, not the entire codebase
  7. Classify REVIEW items precisely — every review_item carries severity, auto_fixable, and requires_human_judgment so the Orchestrator can auto-resolve trivial issues without human input
  8. Artifact-shape match — when a criterion names a specific artifact (file path, screenshot, report), evidence MUST be that artifact or a same-shape facsimile — never a same-property proxy in a different shape. A POST body ≠ state.json excerpt; a source-grep ≠ dist/<name>.js grep; a fixture screenshot ≠ a popup screenshot. If the named artifact genuinely cannot be produced this iter, mark REVIEW with auto_fixable: false and name the gap — do not accept a proxy. (Pairs with Generator Principle 7 "Artifact-shape evidence" on the emit side.)
  9. Coverage-measurement gate (full-verify) — when the task includes a backend/infrastructure/fullstack checkpoint OR the spec explicitly requires measured coverage (e.g. "85% per TESTING.md"), verification-report.md MUST carry numeric coverage_percent in frontmatter. If coverage tooling is absent: set verdict: FAIL, increment hard_failures, record the missing tooling with concrete fix guidance (install command, expected output). Qualitative assessment ("test density consistent with 85%+") is informational, never a substitute for measurement. Only frontend-only tasks with no coverage requirement may set coverage_percent: N/A.

Read the full file on GitHub · 115 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 8d ago First seen · 115 lines · 35 tokens per session scan A b9796655a4b6

Subscribe to this mod's changes

harness-evaluator is an agent published in the GitHub repository stone16/harness-engineering-skills (32 stars, last pushed yesterday), licensed Apache-2.0. It adds 35 tokens to every session and 2,249 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other agents, from other repositories

consistency-qa

The brooks-lint verification gate. Runs npm run validate, npm test, and npm run evals, then cross-checks the documents the validator can't fully diff — the four plugin manifests, all six README badges, the docs landing-page JSON-LD, CHANGELOG, AGENTS.md, GEMINI.md, and the derived book count — for drift. Reports…

hyhmrright/brooks-lint · 123 tokens

eval-curator

Authors and maintains the brooks-lint eval suite in evals/evals.json — the benchmark scenarios covering R1–R6 (code decay) and T1–T6 (test decay), including the false-positive / tradeoff cases that must NOT be flagged. Ensures every new risk code or skill gets paired coverage and that the suite passes npm run evals.…

hyhmrright/brooks-lint · 97 tokens

test-sufficiency

Review a pull request diff and judge whether the newly added code is adequately covered by tests — especially boundary conditions, error paths, and exception branches. Output a short "covered / uncovered" table with specific line-level gaps. Use this agent on PRs that add behavior. It supplements Codex / CodeRabbit…

0xmariowu/AgentLint · 78 tokens

implementer

Executes a single plan task using TDD. Writes tests first, then production code, then refactors. Reports status with evidence.

greglas75/zuvo · 30 tokens

qa-engineer

Assesses testability, identifies risk areas, pre-checks quality gates.

greglas75/zuvo · 19 tokens

quality-reviewer

Evaluates code quality (CQ1-CQ40) and test quality (Q1-Q25) on implemented code. Read-only. Enforces critical gates.

greglas75/zuvo · 36 tokens