Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add chrono-meta/forge-harness --skill harness-doctorgit clone --depth 1 https://github.com/chrono-meta/forge-harnessWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/chrono-meta/forge-harness/harness-doctor)<a href="https://agentmods.dev/skills/chrono-meta/forge-harness/harness-doctor"><img src="https://agentmods.dev/badge/skills/chrono-meta/forge-harness/harness-doctor/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/chrono-meta/forge-harness/harness-doctor"><img src="https://agentmods.dev/badge/skills/chrono-meta/forge-harness/harness-doctor.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00083 | $0.09217 |
| Opus 5 | $0.00042 | $0.04609 |
| Sonnet 5 | $0.00017 | $0.01843 |
| Haiku 4.5 | $0.00008 | $0.00922 |
Grade B, and why
harness-doctor scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Reads agent configuration directoriesmediumAgent snooping
.claude/, .codex/, .gemini/ hold keys, settings and other credentials a mod has no legitimate need for.
done < <(find "$TARGET/.claude/rules" -name '*.md' 2>/dev/null) How it starts
The opening of the file, as written. The whole thing — 514 lines — stays where its author put it; the contents beside it link to each section on GitHub.
harness-doctor — Harness Structure Diagnosis + Prescription
"A good harness gets simpler over time. If it's getting more complex, something is wrong."
Diagnoses harness structural health across 5 layers and proposes M/S/R prescriptions:
- L1 Structural completeness — required file existence (CLAUDE.md · .claudeignore · .claude/)
- L2 Complexity — current state vs. simplification principle (line count · unused files · duplicate definitions)
- L3 Drift — rule vs. actual pattern mismatch (broken references · stale files · conflicting rules)
- L4 Connection diagnosis (FH environment only) — meta hub ↔ field project reference consistency
- L5 Pattern analysis (FH environment only) — skill activity · call context appropriateness · effect metrics
Execution Steps
Step 1. Confirm Diagnostic Target
Check current cwd harness file structure and determine if FH environment (tracks/ + knowledge/ + plugins/ all present).
Step 2. L1 — Structural Completeness
| File | When Missing |
|---|---|
CLAUDE.md |
M-tier — harness entry impossible |
.claudeignore |
S-tier — context-doctor execution recommended |
.claude/ directory |
M-tier (when rule files exist) |
Step 2-E. L1-E — ETCLOVG Layer Coverage (functional-layer lens — orthogonal to the file-presence table above)
A harness is not only files; it is seven functional layers (ETCLOVG — arXiv:2606.06324, a component
taxonomy orthogonal to FH's 6-axis process model; cross-audit
tracks/_audit/session_2026_06_19_harnessfix-etclovg-cross-audit.md). FH adopts only the taxonomy as a
coverage lens — not the paper's scoring model. A coverage checklist, not a mandate: not every
harness needs all seven (a read-only doc harness needs no Execution or Governance). For each layer ask
"is there an asset covering it?"; surface gaps, let the human judge if each is real for this harness.
Orthogonal-sister ledger (same adoption rule — anchor only, no scoring model imported): GRACE (arXiv:2607.09175, cross-audit
tracks/_audit/session_2026_07_24_grace-context-rubric.md, operator-local record) — typed-semantic-graph scoped verification for the C (Context) layer's maintenance path: edits validated only within the modified node's local typed neighborhood. Cite when a C-layer gap involves how context updates are verified, not just whether context assets exist.
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 514 lines · 83 tokens per session scan B 933824cdd9f3
harness-doctor is a skill published in the GitHub repository chrono-meta/forge-harness (14 stars, last pushed today), licensed MIT. It adds 83 tokens to every session and 9,217 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it B with 1 finding (reads agent configuration directories). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
create-issue
Transitional alias — prefer /prflow:specs, which runs the same issue-drafting pipeline. Use when a rough user story, bug report, feature idea, piece of feedback, or an implementation plan should be recorded as a GitHub issue rather than built right now. This command name is retained so existing /prflow:create-issue…
docs-release-notes
Use when a change needs a user-visible release-note, changelog, or changeset entry — "add a release note", "add a changeset for this", "what goes in the changelog?", "write up what shipped", "note this for the next release" — or when finalizing a branch whose customer-visible features, bug fixes, or UI changes should…
retrospective-audit
Stage B of /prflow:retrospective-weekly: given a most-recent-first subset of one recurring pattern's occurrence-PR context bundles (bounded by auditbundlecap), re-derive the root cause and return one JSON object carrying a ranked findings array (one to three sub-patterns) — no edits, no worktree. Invoked as a subagent…
taiyi-health
A codebase health review process that samples recently changed production modules and test files, then checks for issues such as duplication, unused code, and unused dependencies.
remem
Use when the user asks Codex to recall prior project context, save durable decisions or bug fixes, inspect remem memory health, or activate remem automatic memory hooks from the Codex plugin.
rubber-ducky
Use when you've planned a non-trivial change and are about to implement it, finished a complex or multi-file piece of work, just wrote tests, or are stuck on repeated failures — and any time the user says "rubber duck this", "rubber ducky", "get a second opinion", "sanity-check my plan", "poke holes in this", "what am…