harness-tools

Enforce trust-tier governance for MCP tool usage across Linear, Slack, Calendar, Gmail, and analytics.

3|1|Updated Apr 5, 2026
One-click install
npx skills add https://github.com/unclenate/auto-harness --skill harness-tools
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: harness-tools
Source: https://github.com/unclenate/auto-harness/tree/main/platform/skills/harness-tools
Command: npx skills add https://github.com/unclenate/auto-harness --skill harness-tools

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Ensures that actions taken through MCP developer tools follow the project’s trust-tier rules, providing an audit-compatible governance path for tool usage.

Core Features & Use Cases

  • Tool trust-tier enforcement: Classifies each curated MCP tool’s operations into read, workspace write, and externally visible tier levels so human authorization is required for Tier 3 actions.
  • Linear-backed governance artifacts: Uses Linear as the working surface while keeping checked-in docs/ files as the canonical harness artifacts.
  • Companion-rule notification discipline via Slack: Routes companion-rule triggers through Slack only with human approval, preventing unapproved announcements or disclosure.
  • Externally visible scheduling and messaging gates: Restricts Google Calendar and Gmail actions to Tier 3 with review-before-send behavior.
  • Analytics read-only policy: Limits Ahrefs and Similarweb to Tier 0 read-only guidance use, surfacing data for human decision-making rather than autonomous scope/product choices.

Quick Start

Ask the AI to use Linear, Slack, Calendar, or Gmail to draft a harness-governed update and to show the proposed Tier 3 message or event for your approval before it is sent.

Frequently Asked Questions about harness-tools

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I enforce human approval for MCP tool actions before sending external messages?

MCP tool governance enforces human approval by classifying actions into trust tiers, restricting externally visible operations like Gmail and Calendar events to Tier 3 review-before-send behavior. This ensures no external disclosure happens without explicit human instruction.

How do I route Slack companion-rule notifications through a governance review gate?

Slack companion-rule notifications are routed through a governance gate that requires human approval before sending. This discipline prevents unapproved announcements or disclosure by stopping automated messages without explicit consent.

Can I restrict analytics tools like Ahrefs and Similarweb to read-only guidance under MCP governance?

Analytics tools like Ahrefs and Similarweb are limited to Tier 0 read-only guidance use under MCP governance. This surfaces data for human decision-making rather than allowing autonomous scope or product choices.

What is the best way to manage Linear governance artifacts while keeping docs as canonical files?

Linear-backed governance artifacts use Linear as the working surface while maintaining checked-in docs files as the canonical harness artifacts. This synchronization discipline ensures audit-compatible records across both platforms.

Does MCP trust-tier governance support Google Calendar and Gmail actions for external scheduling?

Google Calendar and Gmail actions are supported but restricted to Tier 3 externally visible scheduling and messaging gates. The governance requires review-before-send behavior, meaning all events and messages need explicit human instruction before delivery.

What limitations exist when using MCP tools for externally visible Tier 3 actions?

Tier 3 externally visible actions face stop conditions requiring explicit human instruction for any operation. This means automated workflows cannot execute external disclosures, scheduling, or messaging independently without breaking governance compliance.