exempt-vuln

Create Harness STO security exemptions for vulnerabilities in bulk.

80|16|Updated Mar 11, 2026
One-click install
npx skills add https://github.com/harness/harness-skills --skill exempt-vuln
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: exempt-vuln
Source: https://github.com/harness/harness-skills/tree/main/skills/exempt-vuln
Command: npx skills add https://github.com/harness/harness-skills --skill exempt-vuln

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Automates the creation of security exemptions (waivers) for Harness STO vulnerabilities.

Core Features & Use Cases

  • Bulk and per-issue exemption creation across multiple scopes (This Project, This Pipeline, This Target) and UI views.
  • Per-row tolerance for errors, and support for bulk up to 100 exemptions with all-or-none guarantees.
  • Workflow guides from identification to approval and linking to tickets.

Quick Start

Exempt a vulnerability by creating a single exemption for a chosen issue in a specific scope using a False Positive type.

Frequently Asked Questions about exempt-vuln

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I create a security exemption for a vulnerability in Harness STO?

To create a security exemption for a Harness STO vulnerability, you specify the target issue, scope, and exemption type such as False Positive. The workflow guides field collection, validation, and approval to generate the waiver.

Can I apply bulk security waivers to multiple vulnerabilities at once?

Yes, you can apply bulk security waivers to multiple vulnerabilities at once. The workflow supports creating up to 100 exemptions simultaneously with per-row error tolerance and all-or-none guarantees.

What scopes are supported when waiving CVE vulnerabilities in Harness?

When waiving CVE vulnerabilities in Harness, you can target multiple scopes including This Project, This Pipeline, and This Target. The exemption process enforces scope rules across both the Vulnerabilities tab and All Issues page.

How do I track the status of a security exemption after it is created?

You can track a security exemption status by checking the returned exemption identifiers and deep links. These outputs provide direct access to review the approval workflow and current standing of the waiver.

Does the vulnerability exemption workflow work with the All Issues page?

Yes, the vulnerability exemption workflow works directly with the All Issues page as well as the Vulnerabilities tab view. It enforces scope rules and returns exemption identifiers with deep links for review.

What happens if one vulnerability fails during a bulk exemption creation?

If one vulnerability fails during bulk exemption creation, the workflow provides per-row tolerance for errors. However, it enforces all-or-none guarantees for bulk actions up to 100 items.