Install
$ agentstack add skill-harness-harness-skills-scorecard-review ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Scorecard Review
Review service maturity and compliance scorecards using Harness Internal Developer Portal (IDP) via MCP.
Instructions
Step 1: List Catalog Entities
Call MCP tool: harness_list
Parameters:
resource_type: "idp_entity"
org_id: ""
project_id: ""
Step 2: Get Entity Details
Call MCP tool: harness_get
Parameters:
resource_type: "idp_entity"
resource_id: ""
Step 3: Get Scorecard Scores
Call MCP tool: harness_list
Parameters:
resource_type: "idp_score"
org_id: ""
project_id: ""
Get specific entity score:
Call MCP tool: harness_get
Parameters:
resource_type: "idp_score"
resource_id: ""
Step 4: Check Documentation
Call MCP tool: harness_list
Parameters:
resource_type: "idp_tech_doc"
org_id: ""
project_id: ""
Step 5: Review Workflows
Call MCP tool: harness_list
Parameters:
resource_type: "idp_workflow"
org_id: ""
project_id: ""
Common Scorecard Categories
- Production Readiness - CI/CD, monitoring, alerting, runbooks
- Security Compliance - Vulnerability scanning, secrets management, access control
- Documentation - API docs, architecture diagrams, runbooks
- Operational Excellence - SLOs, incident response, on-call
- Developer Experience - Build times, test coverage, onboarding
Report Format
## Service Scorecard Report
**Service:**
**Overall Score:** X/100
### Category Scores
| Category | Score | Status |
|----------|-------|--------|
| Production Readiness | 85/100 | Pass |
| Security | 70/100 | Needs Work |
| Documentation | 45/100 | Failing |
| Operations | 90/100 | Pass |
### Failing Checks
1. Missing API documentation
2. No SBOM generation configured
3. Test coverage below 80%
### Improvement Actions
1. Add API docs to /docs endpoint
2. Enable SBOM in CI pipeline
3. Increase test coverage to 80%+
IDP Resource Types
| Resource Type | Operations | Description | |--------------|-----------|-------------| | idp_entity | list, get | Catalog entities | | idp_score | list, get | Scorecard scores | | idp_tech_doc | list, get | Technical docs | | idp_workflow | list, get | IDP workflows |
Examples
- "How is api-gateway doing on scorecards?" - Get idp_score for entity
- "Which services are failing production readiness?" - List idp_score, filter by failing
- "Help me improve checkout-service score" - Get score, identify failing checks, suggest fixes
- "Show all services below 80% compliance" - List and filter idp_score
Performance Notes
- Analyze all scorecard checks before recommending improvements. Do not skip failing checks.
- Cross-reference failing checks with the service's actual configuration and documentation.
- Prioritize recommendations by impact — focus on checks that affect production readiness first.
Troubleshooting
No Scores Available
- Verify scorecards are configured in IDP settings
- Check entity is registered in the catalog
- Ensure data sources (CI/CD, monitoring) are connected
Scores Not Updating
- Check integration sync status
- Verify data source connectivity
- Review scorecard rule configuration
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: harness
- Source: harness/harness-skills
- License: Apache-2.0
- Homepage: https://developer.harness.io/docs/platform/harness-ai/harness-skills/
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.