security-report

Aggregate vulnerabilities, SBOMs, and exemptions via MCP for audit-ready security reports.

80|16|Updated Mar 11, 2026
One-click install
npx skills add https://github.com/harness/harness-skills --skill security-report-harness
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-report
Source: https://github.com/harness/harness-skills/tree/main/skills/security-report
Command: npx skills add https://github.com/harness/harness-skills --skill security-report-harness

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill consolidates security findings from Harness SCS and STO via MCP, enabling teams to generate cohesive security compliance reports and track remediation.

Core Features & Use Cases

  • Vulnerability & SBOM Aggregation: List vulnerabilities, fetch details, and retrieve SBOMs for projects.
  • Remediation & Exemption Management: Get remediation guidance and manage security exemptions within MCP.
  • Audit-Ready Reporting: Generate structured, ready-for-audit security reports covering issues, SBOM status, and compliance results.

Quick Start

Generate a security report for your project by invoking the skill and summarizing the latest MCP data.

Frequently Asked Questions about security-report

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate security compliance reporting for vulnerabilities and SBOMs?

Automate security compliance reporting by aggregating vulnerabilities, SBOMs, and exemptions via MCP to produce audit-ready reports. It consolidates findings from Harness SCS and STO, enabling teams to track remediation and generate structured compliance reviews.

Can I retrieve SBOM details and check artifact components using MCP?

Yes, you can retrieve SBOM details and check artifact components using supported MCP operations. The skill lists SBOMs, fetches their details, and verifies artifact components to consolidate security findings for compliance reporting.

How do I get remediation guidance for vulnerabilities found in Harness STO?

Get remediation guidance for vulnerabilities by invoking MCP operations to list and fetch vulnerability details. The skill applies to projects using Harness SCS and STO, obtaining actionable remediation guidance to track and resolve security issues.

Does security-report work with Harness SCS and STO to manage security exemptions?

Yes, security-report works with Harness SCS and STO to manage security exemptions within MCP. It aggregates vulnerability data and exemptions, allowing teams to generate cohesive security compliance reports and track remediation planning.

What is the best way to generate audit-ready security reports for compliance reviews?

The best way to generate audit-ready security reports is by consolidating vulnerability findings, SBOM status, and compliance results via MCP. This skill structures the aggregated security data into a ready-for-audit format covering issues and remediation tracking.

When do I need to use MCP operations for vulnerability aggregation?

Use MCP operations for vulnerability aggregation when you need to consolidate scattered security findings from Harness SCS and STO into a cohesive report. It is necessary for producing audit-ready compliance reports and tracking remediation across projects.