Install
$ agentstack add skill-arnie016-codex-prompt-templates-auto-skill-build-mcp-conformance-harness ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
MCP Conformance Harness
Generated by: Codex Supercharge maintenance automation.
Goal: turn MCP server testing into a repeatable harness with clear evidence, secret handling, and pass/fail gates.
Workflow
- Use
$sandbox-source-intakeand$mcp-safety-reviewbefore running a fresh
MCP server, unknown CLI, install script, or broad-account tool.
- Identify the target matrix:
- transport: HTTP or stdio
- auth: none, static token, OAuth interactive, OAuth headless, or M2M
- checks: doctor, tool surface, protocol, OAuth, apps UI
- Prefer read-only checks first:
server probe,server doctor, and
server export with --no-telemetry and JSON output.
- Add
protocol,oauth, orappsconformance suites only after auth and
blast radius are understood; emit JUnit/XML or JSON summary artifacts.
- Capture before/after
server exportsnapshots and sort them before diffing
when release tool-surface drift is the risk.
- Use the command recipes in
references/mcp-conformance-harness.mdinstead
of expanding long shell blocks into the skill body.
- Store reports as CI artifacts, but keep credentials out of artifacts. Prefer
environment secrets, credentials files with mode 0600, or CI secret stores.
- Summarize failures by phase: transport, auth, protocol, tool schema, apps UI,
or release diff.
Harness Contract
# MCP Harness Plan
Target:
Transport/auth:
Read-only checks:
Conformance suites:
Tool-surface diff:
Secrets:
Artifacts:
Pass/fail gates:
Known skips:
Skip When
- The user only wants to manually explore one server once.
- No MCP endpoint, stdio command, or runnable server target is available.
- The server/tool is untrusted and has not passed source intake or safety review.
- Running the harness would call write/destructive tools without explicit scope.
References
references/mcp-conformance-harness.md- Source inspiration only, code not executed:
sources/mcpjam-inspector - Support skills:
$mcp-server-lab,$mcp-safety-review,$auto-skill-safety-mcp-secret-guard
Validation
plugins/codex-supercharge/scripts/skill_audit.sh plugins/codex-supercharge/skills
python3 "$HOME/.codex/skills/.system/skill-creator/scripts/quick_validate.py" \
plugins/codex-supercharge/skills/auto-skill-build-mcp-conformance-harness
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: Arnie016
- Source: Arnie016/codex-prompt-templates
- License: MIT
- Homepage: https://github.com/Arnie016/codex-prompt-templates
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.