security-report

Generate security compliance reports from Harness SCS and STO vulnerability data.

1|Updated Apr 16, 2026
One-click install
npx skills add https://github.com/thisrohangupta/cursor-harness-plugin --skill security-report-thisrohangupta
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-report
Source: https://github.com/thisrohangupta/cursor-harness-plugin/tree/main/skills/security-report
Command: npx skills add https://github.com/thisrohangupta/cursor-harness-plugin --skill security-report-thisrohangupta

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill simplifies the process of generating security compliance reports by automating the collection of vulnerability data, SBOMs, and compliance results using Harness SCS and STO via MCP.

Core Features & Use Cases

  • Vulnerability Analysis: Automate the collection of vulnerabilities and generate reports on their severity and remediation status.
  • SBOM Management: Retrieve and manage Software Bill of Materials (SBOMs) for detailed application security analysis.
  • Compliance Check: Check compliance results and manage security exemptions within the Harness platform.
  • Use Case: For instance, after a user triggers the skill with "security report", the system generates a comprehensive report including vulnerability summaries, SBOM details, and compliance checks.

Quick Start

Use the security-report skill to generate a security compliance report for the "backend-service" project.

Frequently Asked Questions about security-report

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate security compliance reporting with vulnerability data and SBOMs?

Automate security compliance reporting by collecting vulnerability data, SBOMs, and compliance results from Harness SCS and STO. Generate comprehensive reports covering vulnerability severity, remediation status, and compliance checks for application security audits.

What is needed to generate security reports using Harness SCS and STO?

Generating security reports using Harness SCS and STO requires the Harness MCP v2 server to be configured. Once set up, the system gathers vulnerability data, SBOMs, and compliance results automatically for your application security audits.

Can I retrieve Software Bill of Materials and check compliance exemptions in Harness?

Yes, you can retrieve and manage Software Bill of Materials for detailed application security analysis. The system checks compliance results and manages security exemptions within the Harness platform using MCP tools.

How do I collect vulnerability severity and remediation status for a Harness project?

Collect vulnerability severity and remediation status by triggering the security report generation for a specific Harness project. The system automates vulnerability analysis and outputs a detailed report on the findings.

Does security compliance reporting work without the Harness MCP v2 server?

No, security compliance reporting requires the Harness MCP v2 server to be configured. This server connection is necessary to collect vulnerability data, SBOMs, and compliance results from Harness SCS and STO.

What is the best way to manage security exemptions and compliance checks in Harness?

The best way to manage security exemptions and compliance checks is automating the collection process via Harness SCS and STO. This approach centralizes compliance results and vulnerability data into a single comprehensive report.