Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add paladini/harness-scorenpx agentmods add plugins/paladini/harness-score/claude-codegit clone --depth 1 https://github.com/paladini/harness-scoreGrade A, and why
claude-code scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "harness-score",
"displayName": "Harness Score",
"version": "0.1.0",
"description": "Deterministic harness-maturity audit for your repository: measures AGENTS.md, rules, skills, hooks, sensors, CI, and hygiene against a 5-level maturity model — without any LLM calls — and teaches the agent how to fix every gap.",
"author": {
"name": "Fernando Paladini",
"url": "https://github.com/paladini"
},
"license": "MIT",
"homepage": "https://paladini.github.io/harness-score/",
"repository": "https://github.com/paladini/harness-score",
"keywords": [
"harness-engineering",
"audit",
"maturity",
"rules",
"hooks",
"guardrails",
"ai-assisted-development"
]
}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 23 lines scan A dfa3ba839e2f
claude-code is a plugin published in the GitHub repository paladini/harness-score (199 stars, last pushed 4d ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other plugins, from other repositories
ainb-fleet
LLM-facing skill teaching agents how to spawn ainb sessions correctly and how to use ainb fleet ... orchestration subcommands. Spawning covers the ainb run contract (always into a git worktree, plus the --parent shapes that silently misfire). Fleet covers multi-session broadcast, ack-gated sequence, blocked-sessi.
mako-ai
Project intelligence skills for Claude Code. Teaches Claude when to use Mako's MCP tools (context packets, code and schema search, diagnostics, RLS audits) instead of grep-walking the repo.
skills
Skill discovery, installation, and authoring — find skills with scout, create new universal skills with skill-builder.
failure-memory
Local, cross-agent memory for learning from real failures without treating requirement changes as mistakes.
ironwallet-mcp
The IronWallet MCP server gives AI agents a non-custodial hot wallet on the host machine. Seed phrases stay encrypted locally and never leave the host. Agents can check balances, transfer tokens, and swap across 10+ networks (EVM, Tron, Bitcoin, Litecoin, Dogecoin, Solana, XRP, TON).
spar
Keep learning while AI writes the code. Predict before you are told, then turn every gap between your model and reality into a curriculum.