harness-tools

Enforce trust-tier governance for MCP tool usage across Linear, Slack, Calendar, Gmail, and analytics.

3|1|Updated Apr 5, 2026
One-click install
npx skills add https://github.com/unclenate/auto-harness --skill harness-tools
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: harness-tools
Source: https://github.com/unclenate/auto-harness/tree/main/platform/skills/harness-tools
Command: npx skills add https://github.com/unclenate/auto-harness --skill harness-tools

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Ensures that actions taken through MCP developer tools follow the project’s trust-tier rules, providing an audit-compatible governance path for tool usage.

Core Features & Use Cases

  • Tool trust-tier enforcement: Classifies each curated MCP tool’s operations into read, workspace write, and externally visible tier levels so human authorization is required for Tier 3 actions.
  • Linear-backed governance artifacts: Uses Linear as the working surface while keeping checked-in docs/ files as the canonical harness artifacts.
  • Companion-rule notification discipline via Slack: Routes companion-rule triggers through Slack only with human approval, preventing unapproved announcements or disclosure.
  • Externally visible scheduling and messaging gates: Restricts Google Calendar and Gmail actions to Tier 3 with review-before-send behavior.
  • Analytics read-only policy: Limits Ahrefs and Similarweb to Tier 0 read-only guidance use, surfacing data for human decision-making rather than autonomous scope/product choices.

Quick Start

Ask the AI to use Linear, Slack, Calendar, or Gmail to draft a harness-governed update and to show the proposed Tier 3 message or event for your approval before it is sent.

Frequently Asked Questions about harness-tools

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I enforce human approval for MCP tool actions before sending external messages?▼

MCP tool governance enforces human approval by classifying actions into trust tiers, restricting externally visible operations like Gmail and Calendar events to Tier 3 review-before-send behavior. This ensures no external disclosure happens without explicit human instruction.

How do I route Slack companion-rule notifications through a governance review gate?▼

Slack companion-rule notifications are routed through a governance gate that requires human approval before sending. This discipline prevents unapproved announcements or disclosure by stopping automated messages without explicit consent.

Can I restrict analytics tools like Ahrefs and Similarweb to read-only guidance under MCP governance?▼

Analytics tools like Ahrefs and Similarweb are limited to Tier 0 read-only guidance use under MCP governance. This surfaces data for human decision-making rather than allowing autonomous scope or product choices.

What is the best way to manage Linear governance artifacts while keeping docs as canonical files?▼

Linear-backed governance artifacts use Linear as the working surface while maintaining checked-in docs files as the canonical harness artifacts. This synchronization discipline ensures audit-compatible records across both platforms.

Does MCP trust-tier governance support Google Calendar and Gmail actions for external scheduling?▼

Google Calendar and Gmail actions are supported but restricted to Tier 3 externally visible scheduling and messaging gates. The governance requires review-before-send behavior, meaning all events and messages need explicit human instruction before delivery.

What limitations exist when using MCP tools for externally visible Tier 3 actions?▼

Tier 3 externally visible actions face stop conditions requiring explicit human instruction for any operation. This means automated workflows cannot execute external disclosures, scheduling, or messaging independently without breaking governance compliance.