Repository files navigation

Harness Protocol

Status: v1 Schema layer — candidate

The Harness Protocol is an open specification for portable AI coding harnesses — a vendor-neutral harness.yaml format that captures the complete operational context for an AI coding agent: plugins, skills, MCP servers, environment requirements, behavioral instructions, permissions, and governance policy. It is to AI coding harnesses what the Model Context Protocol (MCP) is to tool communication.

AI coding tools like Claude Code, Cursor, and GitHub Copilot each have their own proprietary formats for capturing agent context. A developer who crafts a well-tuned configuration for one tool cannot share it with a teammate on a different tool, publish it for their team to reuse, or carry it when they switch tools. The Harness Protocol defines a common format so that harness configurations become portable, shareable artifacts — the same way MCP made tool communication portable.


Protocol Layers

The specification is organized into three layers, each building on the previous.

LayerDescriptionStatus
SchemaThe harness.yaml format, JSON Schema validation, security model, plugin manifestv1 — current
ExchangeHarness-to-harness sharing: publish, fetch, and compose harnesses across tools and teamsv2 — accepted (HEP-7)
RegistryHosted discovery at harnessprotocol.io: search, publish, version resolution, integrity verificationv2/v3 — draft (HEP-8)

Layers are intentionally decoupled. A tool can implement Schema-layer validation today without any dependency on exchange or registry infrastructure.


harness.yaml

A harness profile is a YAML file validated against the Harness Protocol JSON Schema. The minimal valid profile:

$schema: https://harnessprotocol.io/schema/v1/harness.schema.jsonversion: "1"metadata:
name: my-harnessdescription: A minimal valid Harness Protocol v1 profile.

A fuller example showing common fields:

$schema: https://harnessprotocol.io/schema/v1/harness.schema.jsonversion: "1"metadata:
name: data-engineerdescription: Harness for data engineering work in Go and SQL.author:
name: acme-orgplugins:
- name: sql-explorersource: acme-org/sql-explorerversion: "^1.2.0"integrity:
sha256: "abc123def456..."mcp-servers:
filesystem:
transport: stdiocommand: npxargs: ["-y", "@modelcontextprotocol/server-filesystem", "/workspace"]env:
- name: DATABASE_URLdescription: Primary database connection stringrequired: truesensitive: trueinstructions:
operational: file://./instructions/operational.mdimport-mode: mergepermissions:
tools:
allow: [Read, Glob, Grep, Write, Edit]deny: ["mcp__*__drop_*"]

The full field reference is in protocol/profile-schema.md. The JSON Schema is the authoritative validation source.


Getting Started

harness-kit is the reference implementation of the Harness Protocol. It provides a parser, validator, plugin loader, MCP server lifecycle manager, and CLI for working with harness.yaml profiles. Start there to use the protocol today.

Conformance does not require harness-kit — any implementation that correctly validates and applies harness.yaml per this specification is conformant.


Documentation

Full documentation is available at harnessprotocol.io/spec.

DocumentContent
protocol/overview.mdWhat the protocol is and how the layers fit together
protocol/terminology.mdGlossary of all terms used in the spec
protocol/architecture.mdSystem diagram, layer interactions, trust model
protocol/profile-schema.mdFull harness.yaml field reference
protocol/plugin-manifest.mdplugin.json format for plugin authors
protocol/mcp-declarations.mdMCP server transport types, variable substitution, security
protocol/instructions.mdInstruction slots, content sources, import modes
protocol/environment.mdEnvironment variable declarations and sensitive data handling
protocol/fragments.mdkind: fragment — partial harness documents for composition
protocol/inheritance.mdextends resolution order and per-section merge rules
protocol/application.mdApplication pipeline, effective configuration, error handling
protocol/source-resolution.mdSource resolution algorithm for owner/repo and local path references
protocol/exchange.md(v2) Exchange layer — the signed offer envelope and consent-first sharing flow
protocol/registry.md(v2 draft) Registry layer — hosted discovery, integrity hashing, and the transparency log
security/threat-model.mdThreat model and security design
security/trust-boundaries.mdTrust boundaries between spec, implementations, profiles, and remote content
security/secrets.mdSensitive variable handling and secrets patterns
security/permissions.mdPermission model and enforcement
security/integrity.mdContent integrity verification
security/instruction-injection.mdInstruction injection threat and mitigations
security/skill-injection.mdSkill behavioral injection threat and mitigations
security/exchange.md(v2) Exchange threat model — authenticity, consent, confidentiality in transit
security/registry.md(v2 draft) Registry threat model — the registry is an index, not a trust anchor
security/crypto-map.mdHow SHA-256 integrity, ed25519 (Exchange), and minisign signing compose

Where to Start

Harness authors (writing harness.yaml files):

  1. protocol/profile-schema.md — the complete field reference
  2. examples/ — annotated example profiles to copy from
  3. schema/draft/harness.schema.json — validate your file

Tool implementers (building a harness implementation):

  1. protocol/overview.md — what the protocol is and how layers fit together
  2. protocol/architecture.md — system model and trust boundaries
  3. protocol/application.md — the 7-step application pipeline
  4. protocol/source-resolution.md — how owner/repo references resolve
  5. protocol/profile-schema.md — the normative field specification
  6. security/ — security model, sensitive data rules, and threat model

Contributing

Spec changes go through the HEP (Harness Enhancement Proposal) process. Editorial fixes can be submitted directly as pull requests. See CONTRIBUTING.md for the full process.

Security

See SECURITY.md for the security policy and responsible disclosure process.

License

Apache License 2.0. See LICENSE.

, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

Harness Protocol

Status: v1 Schema layer — candidate

The Harness Protocol is an open specification for portable AI coding harnesses — a vendor-neutral harness.yaml format that captures the complete operational context for an AI coding agent: plugins, skills, MCP servers, environment requirements, behavioral instructions, permissions, and governance policy. It is to AI coding harnesses what the Model Context Protocol (MCP) is to tool communication.

AI coding tools like Claude Code, Cursor, and GitHub Copilot each have their own proprietary formats for capturing agent context. A developer who crafts a well-tuned configuration for one tool cannot share it with a teammate on a different tool, publish it for their team to reuse, or carry it when they switch tools. The Harness Protocol defines a common format so that harness configurations become portable, shareable artifacts — the same way MCP made tool communication portable.


Protocol Layers

The specification is organized into three layers, each building on the previous.

LayerDescriptionStatus
SchemaThe harness.yaml format, JSON Schema validation, security model, plugin manifestv1 — current
ExchangeHarness-to-harness sharing: publish, fetch, and compose harnesses across tools and teamsv2 — accepted (HEP-7)
RegistryHosted discovery at harnessprotocol.io: search, publish, version resolution, integrity verificationv2/v3 — draft (HEP-8)

Layers are intentionally decoupled. A tool can implement Schema-layer validation today without any dependency on exchange or registry infrastructure.


harness.yaml

A harness profile is a YAML file validated against the Harness Protocol JSON Schema. The minimal valid profile:

$schema: https://harnessprotocol.io/schema/v1/harness.schema.jsonversion: "1"metadata:
name: my-harnessdescription: A minimal valid Harness Protocol v1 profile.

A fuller example showing common fields:

$schema: https://harnessprotocol.io/schema/v1/harness.schema.jsonversion: "1"metadata:
name: data-engineerdescription: Harness for data engineering work in Go and SQL.author:
name: acme-orgplugins:
- name: sql-explorersource: acme-org/sql-explorerversion: "^1.2.0"integrity:
sha256: "abc123def456..."mcp-servers:
filesystem:
transport: stdiocommand: npxargs: ["-y", "@modelcontextprotocol/server-filesystem", "/workspace"]env:
- name: DATABASE_URLdescription: Primary database connection stringrequired: truesensitive: trueinstructions:
operational: file://./instructions/operational.mdimport-mode: mergepermissions:
tools:
allow: [Read, Glob, Grep, Write, Edit]deny: ["mcp__*__drop_*"]

The full field reference is in protocol/profile-schema.md. The JSON Schema is the authoritative validation source.


Getting Started

harness-kit is the reference implementation of the Harness Protocol. It provides a parser, validator, plugin loader, MCP server lifecycle manager, and CLI for working with harness.yaml profiles. Start there to use the protocol today.

Conformance does not require harness-kit — any implementation that correctly validates and applies harness.yaml per this specification is conformant.


Documentation

Full documentation is available at harnessprotocol.io/spec.

DocumentContent
protocol/overview.mdWhat the protocol is and how the layers fit together
protocol/terminology.mdGlossary of all terms used in the spec
protocol/architecture.mdSystem diagram, layer interactions, trust model
protocol/profile-schema.mdFull harness.yaml field reference
protocol/plugin-manifest.mdplugin.json format for plugin authors
protocol/mcp-declarations.mdMCP server transport types, variable substitution, security
protocol/instructions.mdInstruction slots, content sources, import modes
protocol/environment.mdEnvironment variable declarations and sensitive data handling
protocol/fragments.mdkind: fragment — partial harness documents for composition
protocol/inheritance.mdextends resolution order and per-section merge rules
protocol/application.mdApplication pipeline, effective configuration, error handling
protocol/source-resolution.mdSource resolution algorithm for owner/repo and local path references
protocol/exchange.md(v2) Exchange layer — the signed offer envelope and consent-first sharing flow
protocol/registry.md(v2 draft) Registry layer — hosted discovery, integrity hashing, and the transparency log
security/threat-model.mdThreat model and security design
security/trust-boundaries.mdTrust boundaries between spec, implementations, profiles, and remote content
security/secrets.mdSensitive variable handling and secrets patterns
security/permissions.mdPermission model and enforcement
security/integrity.mdContent integrity verification
security/instruction-injection.mdInstruction injection threat and mitigations
security/skill-injection.mdSkill behavioral injection threat and mitigations
security/exchange.md(v2) Exchange threat model — authenticity, consent, confidentiality in transit
security/registry.md(v2 draft) Registry threat model — the registry is an index, not a trust anchor
security/crypto-map.mdHow SHA-256 integrity, ed25519 (Exchange), and minisign signing compose

Where to Start

Harness authors (writing harness.yaml files):

  1. protocol/profile-schema.md — the complete field reference
  2. examples/ — annotated example profiles to copy from
  3. schema/draft/harness.schema.json — validate your file

Tool implementers (building a harness implementation):

  1. protocol/overview.md — what the protocol is and how layers fit together
  2. protocol/architecture.md — system model and trust boundaries
  3. protocol/application.md — the 7-step application pipeline
  4. protocol/source-resolution.md — how owner/repo references resolve
  5. protocol/profile-schema.md — the normative field specification
  6. security/ — security model, sensitive data rules, and threat model

Contributing

Spec changes go through the HEP (Harness Enhancement Proposal) process. Editorial fixes can be submitted directly as pull requests. See CONTRIBUTING.md for the full process.

Security

See SECURITY.md for the security policy and responsible disclosure process.

License

Apache License 2.0. See LICENSE.

, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Harness Protocol

Status: v1 Schema layer — candidate

The Harness Protocol is an open specification for portable AI coding harnesses — a vendor-neutral harness.yaml format that captures the complete operational context for an AI coding agent: plugins, skills, MCP servers, environment requirements, behavioral instructions, permissions, and governance policy. It is to AI coding harnesses what the Model Context Protocol (MCP) is to tool communication.

AI coding tools like Claude Code, Cursor, and GitHub Copilot each have their own proprietary formats for capturing agent context. A developer who crafts a well-tuned configuration for one tool cannot share it with a teammate on a different tool, publish it for their team to reuse, or carry it when they switch tools. The Harness Protocol defines a common format so that harness configurations become portable, shareable artifacts — the same way MCP made tool communication portable.


Protocol Layers

The specification is organized into three layers, each building on the previous.

LayerDescriptionStatus
SchemaThe harness.yaml format, JSON Schema validation, security model, plugin manifestv1 — current
ExchangeHarness-to-harness sharing: publish, fetch, and compose harnesses across tools and teamsv2 — accepted (HEP-7)
RegistryHosted discovery at harnessprotocol.io: search, publish, version resolution, integrity verificationv2/v3 — draft (HEP-8)

Layers are intentionally decoupled. A tool can implement Schema-layer validation today without any dependency on exchange or registry infrastructure.


harness.yaml

A harness profile is a YAML file validated against the Harness Protocol JSON Schema. The minimal valid profile:

$schema: https://harnessprotocol.io/schema/v1/harness.schema.jsonversion: "1"metadata:
name: my-harnessdescription: A minimal valid Harness Protocol v1 profile.

A fuller example showing common fields:

$schema: https://harnessprotocol.io/schema/v1/harness.schema.jsonversion: "1"metadata:
name: data-engineerdescription: Harness for data engineering work in Go and SQL.author:
name: acme-orgplugins:
- name: sql-explorersource: acme-org/sql-explorerversion: "^1.2.0"integrity:
sha256: "abc123def456..."mcp-servers:
filesystem:
transport: stdiocommand: npxargs: ["-y", "@modelcontextprotocol/server-filesystem", "/workspace"]env:
- name: DATABASE_URLdescription: Primary database connection stringrequired: truesensitive: trueinstructions:
operational: file://./instructions/operational.mdimport-mode: mergepermissions:
tools:
allow: [Read, Glob, Grep, Write, Edit]deny: ["mcp__*__drop_*"]

The full field reference is in protocol/profile-schema.md. The JSON Schema is the authoritative validation source.


Getting Started

harness-kit is the reference implementation of the Harness Protocol. It provides a parser, validator, plugin loader, MCP server lifecycle manager, and CLI for working with harness.yaml profiles. Start there to use the protocol today.

Conformance does not require harness-kit — any implementation that correctly validates and applies harness.yaml per this specification is conformant.


Documentation

Full documentation is available at harnessprotocol.io/spec.

DocumentContent
protocol/overview.mdWhat the protocol is and how the layers fit together
protocol/terminology.mdGlossary of all terms used in the spec
protocol/architecture.mdSystem diagram, layer interactions, trust model
protocol/profile-schema.mdFull harness.yaml field reference
protocol/plugin-manifest.mdplugin.json format for plugin authors
protocol/mcp-declarations.mdMCP server transport types, variable substitution, security
protocol/instructions.mdInstruction slots, content sources, import modes
protocol/environment.mdEnvironment variable declarations and sensitive data handling
protocol/fragments.mdkind: fragment — partial harness documents for composition
protocol/inheritance.mdextends resolution order and per-section merge rules
protocol/application.mdApplication pipeline, effective configuration, error handling
protocol/source-resolution.mdSource resolution algorithm for owner/repo and local path references
protocol/exchange.md(v2) Exchange layer — the signed offer envelope and consent-first sharing flow
protocol/registry.md(v2 draft) Registry layer — hosted discovery, integrity hashing, and the transparency log
security/threat-model.mdThreat model and security design
security/trust-boundaries.mdTrust boundaries between spec, implementations, profiles, and remote content
security/secrets.mdSensitive variable handling and secrets patterns
security/permissions.mdPermission model and enforcement
security/integrity.mdContent integrity verification
security/instruction-injection.mdInstruction injection threat and mitigations
security/skill-injection.mdSkill behavioral injection threat and mitigations
security/exchange.md(v2) Exchange threat model — authenticity, consent, confidentiality in transit
security/registry.md(v2 draft) Registry threat model — the registry is an index, not a trust anchor
security/crypto-map.mdHow SHA-256 integrity, ed25519 (Exchange), and minisign signing compose

Where to Start

Harness authors (writing harness.yaml files):

  1. protocol/profile-schema.md — the complete field reference
  2. examples/ — annotated example profiles to copy from
  3. schema/draft/harness.schema.json — validate your file

Tool implementers (building a harness implementation):

  1. protocol/overview.md — what the protocol is and how layers fit together
  2. protocol/architecture.md — system model and trust boundaries
  3. protocol/application.md — the 7-step application pipeline
  4. protocol/source-resolution.md — how owner/repo references resolve
  5. protocol/profile-schema.md — the normative field specification
  6. security/ — security model, sensitive data rules, and threat model

Contributing

Spec changes go through the HEP (Harness Enhancement Proposal) process. Editorial fixes can be submitted directly as pull requests. See CONTRIBUTING.md for the full process.

Security

See SECURITY.md for the security policy and responsible disclosure process.

License

Apache License 2.0. See LICENSE.

, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Harness Protocol

Status: v1 Schema layer — candidate

The Harness Protocol is an open specification for portable AI coding harnesses — a vendor-neutral harness.yaml format that captures the complete operational context for an AI coding agent: plugins, skills, MCP servers, environment requirements, behavioral instructions, permissions, and governance policy. It is to AI coding harnesses what the Model Context Protocol (MCP) is to tool communication.

AI coding tools like Claude Code, Cursor, and GitHub Copilot each have their own proprietary formats for capturing agent context. A developer who crafts a well-tuned configuration for one tool cannot share it with a teammate on a different tool, publish it for their team to reuse, or carry it when they switch tools. The Harness Protocol defines a common format so that harness configurations become portable, shareable artifacts — the same way MCP made tool communication portable.


Protocol Layers

The specification is organized into three layers, each building on the previous.

LayerDescriptionStatus
SchemaThe harness.yaml format, JSON Schema validation, security model, plugin manifestv1 — current
ExchangeHarness-to-harness sharing: publish, fetch, and compose harnesses across tools and teamsv2 — accepted (HEP-7)
RegistryHosted discovery at harnessprotocol.io: search, publish, version resolution, integrity verificationv2/v3 — draft (HEP-8)

Layers are intentionally decoupled. A tool can implement Schema-layer validation today without any dependency on exchange or registry infrastructure.


harness.yaml

A harness profile is a YAML file validated against the Harness Protocol JSON Schema. The minimal valid profile:

$schema: https://harnessprotocol.io/schema/v1/harness.schema.jsonversion: "1"metadata:
name: my-harnessdescription: A minimal valid Harness Protocol v1 profile.

A fuller example showing common fields:

$schema: https://harnessprotocol.io/schema/v1/harness.schema.jsonversion: "1"metadata:
name: data-engineerdescription: Harness for data engineering work in Go and SQL.author:
name: acme-orgplugins:
- name: sql-explorersource: acme-org/sql-explorerversion: "^1.2.0"integrity:
sha256: "abc123def456..."mcp-servers:
filesystem:
transport: stdiocommand: npxargs: ["-y", "@modelcontextprotocol/server-filesystem", "/workspace"]env:
- name: DATABASE_URLdescription: Primary database connection stringrequired: truesensitive: trueinstructions:
operational: file://./instructions/operational.mdimport-mode: mergepermissions:
tools:
allow: [Read, Glob, Grep, Write, Edit]deny: ["mcp__*__drop_*"]

The full field reference is in protocol/profile-schema.md. The JSON Schema is the authoritative validation source.


Getting Started

harness-kit is the reference implementation of the Harness Protocol. It provides a parser, validator, plugin loader, MCP server lifecycle manager, and CLI for working with harness.yaml profiles. Start there to use the protocol today.

Conformance does not require harness-kit — any implementation that correctly validates and applies harness.yaml per this specification is conformant.


Documentation

Full documentation is available at harnessprotocol.io/spec.

DocumentContent
protocol/overview.mdWhat the protocol is and how the layers fit together
protocol/terminology.mdGlossary of all terms used in the spec
protocol/architecture.mdSystem diagram, layer interactions, trust model
protocol/profile-schema.mdFull harness.yaml field reference
protocol/plugin-manifest.mdplugin.json format for plugin authors
protocol/mcp-declarations.mdMCP server transport types, variable substitution, security
protocol/instructions.mdInstruction slots, content sources, import modes
protocol/environment.mdEnvironment variable declarations and sensitive data handling
protocol/fragments.mdkind: fragment — partial harness documents for composition
protocol/inheritance.mdextends resolution order and per-section merge rules
protocol/application.mdApplication pipeline, effective configuration, error handling
protocol/source-resolution.mdSource resolution algorithm for owner/repo and local path references
protocol/exchange.md(v2) Exchange layer — the signed offer envelope and consent-first sharing flow
protocol/registry.md(v2 draft) Registry layer — hosted discovery, integrity hashing, and the transparency log
security/threat-model.mdThreat model and security design
security/trust-boundaries.mdTrust boundaries between spec, implementations, profiles, and remote content
security/secrets.mdSensitive variable handling and secrets patterns
security/permissions.mdPermission model and enforcement
security/integrity.mdContent integrity verification
security/instruction-injection.mdInstruction injection threat and mitigations
security/skill-injection.mdSkill behavioral injection threat and mitigations
security/exchange.md(v2) Exchange threat model — authenticity, consent, confidentiality in transit
security/registry.md(v2 draft) Registry threat model — the registry is an index, not a trust anchor
security/crypto-map.mdHow SHA-256 integrity, ed25519 (Exchange), and minisign signing compose

Where to Start

Harness authors (writing harness.yaml files):

  1. protocol/profile-schema.md — the complete field reference
  2. examples/ — annotated example profiles to copy from
  3. schema/draft/harness.schema.json — validate your file

Tool implementers (building a harness implementation):

  1. protocol/overview.md — what the protocol is and how layers fit together
  2. protocol/architecture.md — system model and trust boundaries
  3. protocol/application.md — the 7-step application pipeline
  4. protocol/source-resolution.md — how owner/repo references resolve
  5. protocol/profile-schema.md — the normative field specification
  6. security/ — security model, sensitive data rules, and threat model

Contributing

Spec changes go through the HEP (Harness Enhancement Proposal) process. Editorial fixes can be submitted directly as pull requests. See CONTRIBUTING.md for the full process.

Security

See SECURITY.md for the security policy and responsible disclosure process.

License

Apache License 2.0. See LICENSE.

, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

Harness Protocol

Status: v1 Schema layer — candidate

The Harness Protocol is an open specification for portable AI coding harnesses — a vendor-neutral harness.yaml format that captures the complete operational context for an AI coding agent: plugins, skills, MCP servers, environment requirements, behavioral instructions, permissions, and governance policy. It is to AI coding harnesses what the Model Context Protocol (MCP) is to tool communication.

AI coding tools like Claude Code, Cursor, and GitHub Copilot each have their own proprietary formats for capturing agent context. A developer who crafts a well-tuned configuration for one tool cannot share it with a teammate on a different tool, publish it for their team to reuse, or carry it when they switch tools. The Harness Protocol defines a common format so that harness configurations become portable, shareable artifacts — the same way MCP made tool communication portable.


Protocol Layers

The specification is organized into three layers, each building on the previous.

LayerDescriptionStatus
SchemaThe harness.yaml format, JSON Schema validation, security model, plugin manifestv1 — current
ExchangeHarness-to-harness sharing: publish, fetch, and compose harnesses across tools and teamsv2 — accepted (HEP-7)
RegistryHosted discovery at harnessprotocol.io: search, publish, version resolution, integrity verificationv2/v3 — draft (HEP-8)

Layers are intentionally decoupled. A tool can implement Schema-layer validation today without any dependency on exchange or registry infrastructure.


harness.yaml

A harness profile is a YAML file validated against the Harness Protocol JSON Schema. The minimal valid profile:

$schema: https://harnessprotocol.io/schema/v1/harness.schema.jsonversion: "1"metadata:
name: my-harnessdescription: A minimal valid Harness Protocol v1 profile.

A fuller example showing common fields:

$schema: https://harnessprotocol.io/schema/v1/harness.schema.jsonversion: "1"metadata:
name: data-engineerdescription: Harness for data engineering work in Go and SQL.author:
name: acme-orgplugins:
- name: sql-explorersource: acme-org/sql-explorerversion: "^1.2.0"integrity:
sha256: "abc123def456..."mcp-servers:
filesystem:
transport: stdiocommand: npxargs: ["-y", "@modelcontextprotocol/server-filesystem", "/workspace"]env:
- name: DATABASE_URLdescription: Primary database connection stringrequired: truesensitive: trueinstructions:
operational: file://./instructions/operational.mdimport-mode: mergepermissions:
tools:
allow: [Read, Glob, Grep, Write, Edit]deny: ["mcp__*__drop_*"]

The full field reference is in protocol/profile-schema.md. The JSON Schema is the authoritative validation source.


Getting Started

harness-kit is the reference implementation of the Harness Protocol. It provides a parser, validator, plugin loader, MCP server lifecycle manager, and CLI for working with harness.yaml profiles. Start there to use the protocol today.

Conformance does not require harness-kit — any implementation that correctly validates and applies harness.yaml per this specification is conformant.


Documentation

Full documentation is available at harnessprotocol.io/spec.

DocumentContent
protocol/overview.mdWhat the protocol is and how the layers fit together
protocol/terminology.mdGlossary of all terms used in the spec
protocol/architecture.mdSystem diagram, layer interactions, trust model
protocol/profile-schema.mdFull harness.yaml field reference
protocol/plugin-manifest.mdplugin.json format for plugin authors
protocol/mcp-declarations.mdMCP server transport types, variable substitution, security
protocol/instructions.mdInstruction slots, content sources, import modes
protocol/environment.mdEnvironment variable declarations and sensitive data handling
protocol/fragments.mdkind: fragment — partial harness documents for composition
protocol/inheritance.mdextends resolution order and per-section merge rules
protocol/application.mdApplication pipeline, effective configuration, error handling
protocol/source-resolution.mdSource resolution algorithm for owner/repo and local path references
protocol/exchange.md(v2) Exchange layer — the signed offer envelope and consent-first sharing flow
protocol/registry.md(v2 draft) Registry layer — hosted discovery, integrity hashing, and the transparency log
security/threat-model.mdThreat model and security design
security/trust-boundaries.mdTrust boundaries between spec, implementations, profiles, and remote content
security/secrets.mdSensitive variable handling and secrets patterns
security/permissions.mdPermission model and enforcement
security/integrity.mdContent integrity verification
security/instruction-injection.mdInstruction injection threat and mitigations
security/skill-injection.mdSkill behavioral injection threat and mitigations
security/exchange.md(v2) Exchange threat model — authenticity, consent, confidentiality in transit
security/registry.md(v2 draft) Registry threat model — the registry is an index, not a trust anchor
security/crypto-map.mdHow SHA-256 integrity, ed25519 (Exchange), and minisign signing compose

Where to Start

Harness authors (writing harness.yaml files):

  1. protocol/profile-schema.md — the complete field reference
  2. examples/ — annotated example profiles to copy from
  3. schema/draft/harness.schema.json — validate your file

Tool implementers (building a harness implementation):

  1. protocol/overview.md — what the protocol is and how layers fit together
  2. protocol/architecture.md — system model and trust boundaries
  3. protocol/application.md — the 7-step application pipeline
  4. protocol/source-resolution.md — how owner/repo references resolve
  5. protocol/profile-schema.md — the normative field specification
  6. security/ — security model, sensitive data rules, and threat model

Contributing

Spec changes go through the HEP (Harness Enhancement Proposal) process. Editorial fixes can be submitted directly as pull requests. See CONTRIBUTING.md for the full process.

Security

See SECURITY.md for the security policy and responsible disclosure process.

License

Apache License 2.0. See LICENSE.

, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Harness Protocol

Status: v1 Schema layer — candidate

The Harness Protocol is an open specification for portable AI coding harnesses — a vendor-neutral harness.yaml format that captures the complete operational context for an AI coding agent: plugins, skills, MCP servers, environment requirements, behavioral instructions, permissions, and governance policy. It is to AI coding harnesses what the Model Context Protocol (MCP) is to tool communication.

AI coding tools like Claude Code, Cursor, and GitHub Copilot each have their own proprietary formats for capturing agent context. A developer who crafts a well-tuned configuration for one tool cannot share it with a teammate on a different tool, publish it for their team to reuse, or carry it when they switch tools. The Harness Protocol defines a common format so that harness configurations become portable, shareable artifacts — the same way MCP made tool communication portable.


Protocol Layers

The specification is organized into three layers, each building on the previous.

LayerDescriptionStatus
SchemaThe harness.yaml format, JSON Schema validation, security model, plugin manifestv1 — current
ExchangeHarness-to-harness sharing: publish, fetch, and compose harnesses across tools and teamsv2 — accepted (HEP-7)
RegistryHosted discovery at harnessprotocol.io: search, publish, version resolution, integrity verificationv2/v3 — draft (HEP-8)

Layers are intentionally decoupled. A tool can implement Schema-layer validation today without any dependency on exchange or registry infrastructure.


harness.yaml

A harness profile is a YAML file validated against the Harness Protocol JSON Schema. The minimal valid profile:

$schema: https://harnessprotocol.io/schema/v1/harness.schema.jsonversion: "1"metadata:
name: my-harnessdescription: A minimal valid Harness Protocol v1 profile.

A fuller example showing common fields:

$schema: https://harnessprotocol.io/schema/v1/harness.schema.jsonversion: "1"metadata:
name: data-engineerdescription: Harness for data engineering work in Go and SQL.author:
name: acme-orgplugins:
- name: sql-explorersource: acme-org/sql-explorerversion: "^1.2.0"integrity:
sha256: "abc123def456..."mcp-servers:
filesystem:
transport: stdiocommand: npxargs: ["-y", "@modelcontextprotocol/server-filesystem", "/workspace"]env:
- name: DATABASE_URLdescription: Primary database connection stringrequired: truesensitive: trueinstructions:
operational: file://./instructions/operational.mdimport-mode: mergepermissions:
tools:
allow: [Read, Glob, Grep, Write, Edit]deny: ["mcp__*__drop_*"]

The full field reference is in protocol/profile-schema.md. The JSON Schema is the authoritative validation source.


Getting Started

harness-kit is the reference implementation of the Harness Protocol. It provides a parser, validator, plugin loader, MCP server lifecycle manager, and CLI for working with harness.yaml profiles. Start there to use the protocol today.

Conformance does not require harness-kit — any implementation that correctly validates and applies harness.yaml per this specification is conformant.


Documentation

Full documentation is available at harnessprotocol.io/spec.

DocumentContent
protocol/overview.mdWhat the protocol is and how the layers fit together
protocol/terminology.mdGlossary of all terms used in the spec
protocol/architecture.mdSystem diagram, layer interactions, trust model
protocol/profile-schema.mdFull harness.yaml field reference
protocol/plugin-manifest.mdplugin.json format for plugin authors
protocol/mcp-declarations.mdMCP server transport types, variable substitution, security
protocol/instructions.mdInstruction slots, content sources, import modes
protocol/environment.mdEnvironment variable declarations and sensitive data handling
protocol/fragments.mdkind: fragment — partial harness documents for composition
protocol/inheritance.mdextends resolution order and per-section merge rules
protocol/application.mdApplication pipeline, effective configuration, error handling
protocol/source-resolution.mdSource resolution algorithm for owner/repo and local path references
protocol/exchange.md(v2) Exchange layer — the signed offer envelope and consent-first sharing flow
protocol/registry.md(v2 draft) Registry layer — hosted discovery, integrity hashing, and the transparency log
security/threat-model.mdThreat model and security design
security/trust-boundaries.mdTrust boundaries between spec, implementations, profiles, and remote content
security/secrets.mdSensitive variable handling and secrets patterns
security/permissions.mdPermission model and enforcement
security/integrity.mdContent integrity verification
security/instruction-injection.mdInstruction injection threat and mitigations
security/skill-injection.mdSkill behavioral injection threat and mitigations
security/exchange.md(v2) Exchange threat model — authenticity, consent, confidentiality in transit
security/registry.md(v2 draft) Registry threat model — the registry is an index, not a trust anchor
security/crypto-map.mdHow SHA-256 integrity, ed25519 (Exchange), and minisign signing compose

Where to Start

Harness authors (writing harness.yaml files):

  1. protocol/profile-schema.md — the complete field reference
  2. examples/ — annotated example profiles to copy from
  3. schema/draft/harness.schema.json — validate your file

Tool implementers (building a harness implementation):

  1. protocol/overview.md — what the protocol is and how layers fit together
  2. protocol/architecture.md — system model and trust boundaries
  3. protocol/application.md — the 7-step application pipeline
  4. protocol/source-resolution.md — how owner/repo references resolve
  5. protocol/profile-schema.md — the normative field specification
  6. security/ — security model, sensitive data rules, and threat model

Contributing

Spec changes go through the HEP (Harness Enhancement Proposal) process. Editorial fixes can be submitted directly as pull requests. See CONTRIBUTING.md for the full process.

Security

See SECURITY.md for the security policy and responsible disclosure process.

License

Apache License 2.0. See LICENSE.

, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Harness Protocol

Status: v1 Schema layer — candidate

The Harness Protocol is an open specification for portable AI coding harnesses — a vendor-neutral harness.yaml format that captures the complete operational context for an AI coding agent: plugins, skills, MCP servers, environment requirements, behavioral instructions, permissions, and governance policy. It is to AI coding harnesses what the Model Context Protocol (MCP) is to tool communication.

AI coding tools like Claude Code, Cursor, and GitHub Copilot each have their own proprietary formats for capturing agent context. A developer who crafts a well-tuned configuration for one tool cannot share it with a teammate on a different tool, publish it for their team to reuse, or carry it when they switch tools. The Harness Protocol defines a common format so that harness configurations become portable, shareable artifacts — the same way MCP made tool communication portable.


Protocol Layers

The specification is organized into three layers, each building on the previous.

LayerDescriptionStatus
SchemaThe harness.yaml format, JSON Schema validation, security model, plugin manifestv1 — current
ExchangeHarness-to-harness sharing: publish, fetch, and compose harnesses across tools and teamsv2 — accepted (HEP-7)
RegistryHosted discovery at harnessprotocol.io: search, publish, version resolution, integrity verificationv2/v3 — draft (HEP-8)

Layers are intentionally decoupled. A tool can implement Schema-layer validation today without any dependency on exchange or registry infrastructure.


harness.yaml

A harness profile is a YAML file validated against the Harness Protocol JSON Schema. The minimal valid profile:

$schema: https://harnessprotocol.io/schema/v1/harness.schema.jsonversion: "1"metadata:
name: my-harnessdescription: A minimal valid Harness Protocol v1 profile.

A fuller example showing common fields:

$schema: https://harnessprotocol.io/schema/v1/harness.schema.jsonversion: "1"metadata:
name: data-engineerdescription: Harness for data engineering work in Go and SQL.author:
name: acme-orgplugins:
- name: sql-explorersource: acme-org/sql-explorerversion: "^1.2.0"integrity:
sha256: "abc123def456..."mcp-servers:
filesystem:
transport: stdiocommand: npxargs: ["-y", "@modelcontextprotocol/server-filesystem", "/workspace"]env:
- name: DATABASE_URLdescription: Primary database connection stringrequired: truesensitive: trueinstructions:
operational: file://./instructions/operational.mdimport-mode: mergepermissions:
tools:
allow: [Read, Glob, Grep, Write, Edit]deny: ["mcp__*__drop_*"]

The full field reference is in protocol/profile-schema.md. The JSON Schema is the authoritative validation source.


Getting Started

harness-kit is the reference implementation of the Harness Protocol. It provides a parser, validator, plugin loader, MCP server lifecycle manager, and CLI for working with harness.yaml profiles. Start there to use the protocol today.

Conformance does not require harness-kit — any implementation that correctly validates and applies harness.yaml per this specification is conformant.


Documentation

Full documentation is available at harnessprotocol.io/spec.

DocumentContent
protocol/overview.mdWhat the protocol is and how the layers fit together
protocol/terminology.mdGlossary of all terms used in the spec
protocol/architecture.mdSystem diagram, layer interactions, trust model
protocol/profile-schema.mdFull harness.yaml field reference
protocol/plugin-manifest.mdplugin.json format for plugin authors
protocol/mcp-declarations.mdMCP server transport types, variable substitution, security
protocol/instructions.mdInstruction slots, content sources, import modes
protocol/environment.mdEnvironment variable declarations and sensitive data handling
protocol/fragments.mdkind: fragment — partial harness documents for composition
protocol/inheritance.mdextends resolution order and per-section merge rules
protocol/application.mdApplication pipeline, effective configuration, error handling
protocol/source-resolution.mdSource resolution algorithm for owner/repo and local path references
protocol/exchange.md(v2) Exchange layer — the signed offer envelope and consent-first sharing flow
protocol/registry.md(v2 draft) Registry layer — hosted discovery, integrity hashing, and the transparency log
security/threat-model.mdThreat model and security design
security/trust-boundaries.mdTrust boundaries between spec, implementations, profiles, and remote content
security/secrets.mdSensitive variable handling and secrets patterns
security/permissions.mdPermission model and enforcement
security/integrity.mdContent integrity verification
security/instruction-injection.mdInstruction injection threat and mitigations
security/skill-injection.mdSkill behavioral injection threat and mitigations
security/exchange.md(v2) Exchange threat model — authenticity, consent, confidentiality in transit
security/registry.md(v2 draft) Registry threat model — the registry is an index, not a trust anchor
security/crypto-map.mdHow SHA-256 integrity, ed25519 (Exchange), and minisign signing compose

Where to Start

Harness authors (writing harness.yaml files):

  1. protocol/profile-schema.md — the complete field reference
  2. examples/ — annotated example profiles to copy from
  3. schema/draft/harness.schema.json — validate your file

Tool implementers (building a harness implementation):

  1. protocol/overview.md — what the protocol is and how layers fit together
  2. protocol/architecture.md — system model and trust boundaries
  3. protocol/application.md — the 7-step application pipeline
  4. protocol/source-resolution.md — how owner/repo references resolve
  5. protocol/profile-schema.md — the normative field specification
  6. security/ — security model, sensitive data rules, and threat model

Contributing

Spec changes go through the HEP (Harness Enhancement Proposal) process. Editorial fixes can be submitted directly as pull requests. See CONTRIBUTING.md for the full process.

Security

See SECURITY.md for the security policy and responsible disclosure process.

License

Apache License 2.0. See LICENSE.

, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

Harness Protocol

Status: v1 Schema layer — candidate

The Harness Protocol is an open specification for portable AI coding harnesses — a vendor-neutral harness.yaml format that captures the complete operational context for an AI coding agent: plugins, skills, MCP servers, environment requirements, behavioral instructions, permissions, and governance policy. It is to AI coding harnesses what the Model Context Protocol (MCP) is to tool communication.

AI coding tools like Claude Code, Cursor, and GitHub Copilot each have their own proprietary formats for capturing agent context. A developer who crafts a well-tuned configuration for one tool cannot share it with a teammate on a different tool, publish it for their team to reuse, or carry it when they switch tools. The Harness Protocol defines a common format so that harness configurations become portable, shareable artifacts — the same way MCP made tool communication portable.


Protocol Layers

The specification is organized into three layers, each building on the previous.

LayerDescriptionStatus
SchemaThe harness.yaml format, JSON Schema validation, security model, plugin manifestv1 — current
ExchangeHarness-to-harness sharing: publish, fetch, and compose harnesses across tools and teamsv2 — accepted (HEP-7)
RegistryHosted discovery at harnessprotocol.io: search, publish, version resolution, integrity verificationv2/v3 — draft (HEP-8)

Layers are intentionally decoupled. A tool can implement Schema-layer validation today without any dependency on exchange or registry infrastructure.


harness.yaml

A harness profile is a YAML file validated against the Harness Protocol JSON Schema. The minimal valid profile:

$schema: https://harnessprotocol.io/schema/v1/harness.schema.jsonversion: "1"metadata:
name: my-harnessdescription: A minimal valid Harness Protocol v1 profile.

A fuller example showing common fields:

$schema: https://harnessprotocol.io/schema/v1/harness.schema.jsonversion: "1"metadata:
name: data-engineerdescription: Harness for data engineering work in Go and SQL.author:
name: acme-orgplugins:
- name: sql-explorersource: acme-org/sql-explorerversion: "^1.2.0"integrity:
sha256: "abc123def456..."mcp-servers:
filesystem:
transport: stdiocommand: npxargs: ["-y", "@modelcontextprotocol/server-filesystem", "/workspace"]env:
- name: DATABASE_URLdescription: Primary database connection stringrequired: truesensitive: trueinstructions:
operational: file://./instructions/operational.mdimport-mode: mergepermissions:
tools:
allow: [Read, Glob, Grep, Write, Edit]deny: ["mcp__*__drop_*"]

The full field reference is in protocol/profile-schema.md. The JSON Schema is the authoritative validation source.


Getting Started

harness-kit is the reference implementation of the Harness Protocol. It provides a parser, validator, plugin loader, MCP server lifecycle manager, and CLI for working with harness.yaml profiles. Start there to use the protocol today.

Conformance does not require harness-kit — any implementation that correctly validates and applies harness.yaml per this specification is conformant.


Documentation

Full documentation is available at harnessprotocol.io/spec.

DocumentContent
protocol/overview.mdWhat the protocol is and how the layers fit together
protocol/terminology.mdGlossary of all terms used in the spec
protocol/architecture.mdSystem diagram, layer interactions, trust model
protocol/profile-schema.mdFull harness.yaml field reference
protocol/plugin-manifest.mdplugin.json format for plugin authors
protocol/mcp-declarations.mdMCP server transport types, variable substitution, security
protocol/instructions.mdInstruction slots, content sources, import modes
protocol/environment.mdEnvironment variable declarations and sensitive data handling
protocol/fragments.mdkind: fragment — partial harness documents for composition
protocol/inheritance.mdextends resolution order and per-section merge rules
protocol/application.mdApplication pipeline, effective configuration, error handling
protocol/source-resolution.mdSource resolution algorithm for owner/repo and local path references
protocol/exchange.md(v2) Exchange layer — the signed offer envelope and consent-first sharing flow
protocol/registry.md(v2 draft) Registry layer — hosted discovery, integrity hashing, and the transparency log
security/threat-model.mdThreat model and security design
security/trust-boundaries.mdTrust boundaries between spec, implementations, profiles, and remote content
security/secrets.mdSensitive variable handling and secrets patterns
security/permissions.mdPermission model and enforcement
security/integrity.mdContent integrity verification
security/instruction-injection.mdInstruction injection threat and mitigations
security/skill-injection.mdSkill behavioral injection threat and mitigations
security/exchange.md(v2) Exchange threat model — authenticity, consent, confidentiality in transit
security/registry.md(v2 draft) Registry threat model — the registry is an index, not a trust anchor
security/crypto-map.mdHow SHA-256 integrity, ed25519 (Exchange), and minisign signing compose

Where to Start

Harness authors (writing harness.yaml files):

  1. protocol/profile-schema.md — the complete field reference
  2. examples/ — annotated example profiles to copy from
  3. schema/draft/harness.schema.json — validate your file

Tool implementers (building a harness implementation):

  1. protocol/overview.md — what the protocol is and how layers fit together
  2. protocol/architecture.md — system model and trust boundaries
  3. protocol/application.md — the 7-step application pipeline
  4. protocol/source-resolution.md — how owner/repo references resolve
  5. protocol/profile-schema.md — the normative field specification
  6. security/ — security model, sensitive data rules, and threat model

Contributing

Spec changes go through the HEP (Harness Enhancement Proposal) process. Editorial fixes can be submitted directly as pull requests. See CONTRIBUTING.md for the full process.

Security

See SECURITY.md for the security policy and responsible disclosure process.

License

Apache License 2.0. See LICENSE.