publish

publish is a skill for Claude Code, Codex from harbor-framework/harbor. It costs 35 tokens per session (853 once invoked), scanned A, original, Apache-2.0.

Instructions for publishing Harbor tasks or datasets to a shared registry. A task is a defined work item, while a dataset is a collection of data used for testing or evaluation.

In plain words
What is it for?
Use them to publish one or more Harbor tasks, initialize dataset metadata, update task identifiers, and upload datasets.
Why use it?
They help check login status and required identifiers before uploading, reducing failures caused by incomplete metadata or incorrect commands.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/harbor-framework/harbor/publish
Any agent
npx skills add harbor-framework/harbor --skill publish
Clone the repo
git clone --depth 1 https://github.com/harbor-framework/harbor

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for publish

README.md
[![agentmods](https://agentmods.dev/badge/skills/harbor-framework/harbor/publish.svg)](https://agentmods.dev/skills/harbor-framework/harbor/publish)
Your own site
<a href="https://agentmods.dev/skills/harbor-framework/harbor/publish"><img src="https://agentmods.dev/badge/skills/harbor-framework/harbor/publish.svg" alt="Measured on agentmods" height="20"></a>
Per session 35 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 853 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00035 $0.00853
Opus 5 $0.00017 $0.00426
Sonnet 5 $0.00007 $0.00171
Haiku 4.5 $0.00003 $0.00085

Measured 3d ago against content hash 7a2a581a29ea, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

publish scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

Origin

Copies of this mod

2 near-identical copies found in the catalogue:

  • publish — 95% identical, 1 lines differ
  • publish — 95% identical, 1 lines differ
skills/publish/SKILL.md · 97 lines

How it starts

The opening of the file, as written. The whole thing — 97 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Help the user publish a Harbor task or dataset to the registry. Walk them through each step, checking prerequisites and confirming before running publish commands.

All commands use uvx harbor so the user does not need to install the CLI globally.

Prerequisites

  1. Auth: Ensure the user is logged in by running uvx harbor auth status. If not logged in, prompt them to run uvx harbor auth login.

  2. Task identifiers: All tasks must have a [task] section in their task.toml with a name like <org>/<name>. If missing, run:

    uvx harbor task update "<path/to/task>" --org "<org>"
    

    To update all tasks in a directory:

    uvx harbor task update "<path/to/tasks>" --org "<org>" --scan
    

Publishing a task

uvx harbor publish "<path/to/task>"

Publish multiple tasks or all tasks in a directory:

uvx harbor publish "<path/to/task-a>" "<path/to/task-b>"
uvx harbor publish "<path/to/tasks>"

Publishing a dataset

1. Initialize the dataset manifest (if no dataset.toml exists)

uvx harbor dataset init "<org>/<dataset>" \
  --description "<description>" \
  --author "Jane Doe <[email protected]>"

Add --with-metric if the user needs a custom metric script. If omitted, the dataset uses the default metric (average reward across tasks, with missing values treated as 0).

Auto-add behavior: If dataset init is run in a directory that already contains tasks, those tasks are automatically added to the manifest. After init, ask the user if they want to add additional tasks — either from the Harbor registry or from other local folders.

2. Add additional tasks and files (optional)

cd "<path/to/dataset>"
uvx harbor add "<path/to/task-a>" "<path/to/task-b>"   # local tasks from elsewhere
uvx harbor add "<path/to/folder>" --scan                 # all tasks in another folder
uvx harbor add org/task-name                             # published tasks from registry
uvx harbor add org/dataset-name                          # all tasks from a published dataset
uvx harbor add metric.py                                 # metric file (same dir as dataset.toml)
uvx harbor remove "<org>/<task-name>"                     # remove a task

Read the full file on GitHub · 97 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 3d ago First seen · 97 lines · 35 tokens per session scan A 7a2a581a29ea

Subscribe to this mod's changes

publish is a skill published in the GitHub repository harbor-framework/harbor (4,854 stars, last pushed yesterday), licensed Apache-2.0. It adds 35 tokens to every session and 853 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.