Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add vasuag09/harness-claude --skill harness-maintaingit clone --depth 1 https://github.com/vasuag09/harness-claudeWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/vasuag09/harness-claude/harness-maintain)<a href="https://agentmods.dev/skills/vasuag09/harness-claude/harness-maintain"><img src="https://agentmods.dev/badge/skills/vasuag09/harness-claude/harness-maintain/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/vasuag09/harness-claude/harness-maintain"><img src="https://agentmods.dev/badge/skills/vasuag09/harness-claude/harness-maintain.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00077 | $0.00417 |
| Opus 5 | $0.00039 | $0.00209 |
| Sonnet 5 | $0.00015 | $0.00083 |
| Haiku 4.5 | $0.00008 | $0.00042 |
Grade A, and why
harness-maintain scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
/harness-maintain — run the Maintain phase
Thin orchestrator over the Maintain skills. Behavior-preserving by default.
Sequence
-
/harness-claude:onboard— only if the codebase is unfamiliar or you've been away from it. Build a lean codemap (structure, entry points, conventions, where things live) so cleanup is safe. If you already know the codebase, skip and say so. -
/harness-claude:refactor-clean— delegate to theharness-claude:refactor-cleaneragent:- Find candidates with analyzers (knip/depcheck/ts-prune/ruff/vulture) or the graph.
- Confirm truly unused before deleting (all references, dynamic usage).
- Consolidate duplication (DRY); split files >800 lines by responsibility.
- Small reversible steps; run tests/build after each.
-
Ambiguity gate: if a deletion or consolidation is non-obvious or could change behavior, HALT — report it and let the user decide. When a "cleanup" turns into a redesign, route to
/harness-claude:architectinstead.
Rules
- Behavior-preserving only. No feature/API changes unless asked.
- Never delete something you didn't confirm unused.
- Keep diffs reviewable. Do not run git write operations.
Output
What was removed/consolidated (with reference checks), what was deliberately left, and confirmation tests/build still pass.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 34 lines · 77 tokens per session scan A b8cb5aca8978
harness-maintain is a skill published in the GitHub repository vasuag09/harness-claude (2 stars, last pushed 2mo ago), licensed MIT. It adds 77 tokens to every session and 417 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
issue-triage
3-phase issue backlog management with audit, deep analysis, and validated triage actions. Use when triaging GitHub issues, sorting bug reports, cleaning up stale tickets, or detecting duplicate issues. Args: 'all' to analyze all, issue numbers to focus (e.g. '42 57'), 'en'/'fr' for language, no arg = audit only.
check-cache-bugs
Audit Claude Code setup for cache bugs (CC#40524): sentinel, --resume/--continue, attribution header + ArkNill B3/B4/B5.
eval-rules
Audit .claude/rules/ files for structural correctness, glob validity, and real-world usefulness. Resolves each paths: pattern against actual project files, then asks the user whether each rule is still relevant and useful. Can update rules in-place based on answers. Use when setting up rules for the first time…
audit-codebase
Codebase health audit scoring 7 categories with progression plan.
pentest-forensics
Digital forensics — evidence acquisition, memory/disk imaging analysis, timeline reconstruction, IOC extraction advisory. Triggers on forensics, DFIR, Volatility, memory analysis, disk image, Autopsy, FTK, timeline, IOC extraction, evidence chain, log analysis.
pentest-malware
Malware analysis — triage, static analysis, dynamic sandbox, IOC extract, YARA signature writing advisory. Triggers on malware analiz, malware triage, sandbox, Cuckoo, IDA, Ghidra, dynamic analysis, IOC, YARA imza, packer, unpacker, reverse malware.