by RealZST
More than a skill manager — manage skills, MCP servers, plugins, hooks, CLIs, configs, memory & rules across every AI coding agent. 🌟 Star if you like it!
# Add to your Claude Code skills
git clone https://github.com/RealZST/HarnessKitLast scanned: 5/30/2026
{
"issues": [
{
"type": "npm-audit",
"message": "basic-ftp: basic-ftp vulnerable to denial of service via unbounded memory consumption in Client.list()",
"severity": "high"
},
{
"type": "npm-audit",
"message": "ip-address: ip-address has XSS in Address6 HTML-emitting methods",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "postcss: PostCSS has XSS via Unescaped </style> in its CSS Stringify Output",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "vite: Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling",
"severity": "high"
},
{
"type": "npm-audit",
"message": "ws: ws: Uninitialized memory disclosure",
"severity": "medium"
}
],
"status": "WARNING",
"scannedAt": "2026-05-30T15:09:02.431Z",
"npmAuditRan": true,
"pipAuditRan": true
}No comments yet. Be the first to share your thoughts!
Every agent, a different world. Extensions, configs, memory, and rules — scattered across different directories, in different formats, with different conventions.
HarnessKit brings them all under one roof — see, secure, and manage everything across every agent, from one place.
HarnessKit manages all five extension types from a unified interface — Skills, MCP Servers, Plugins, Hooks, and Agent-first CLIs.
| Agent | Skills | MCP | Plugins | Hooks | Agent-first CLIs | |:---|:---:|:---:|:---:|:---:|:---:| | Claude Code | ✓ | ✓ | ✓ | ✓ | ✓ | | Codex | ✓ | ✓ | ✓ | ✓ | ✓ | | Gemini CLI | ✓ | ✓ | ✓ | ✓ | ✓ | | Cursor | ✓ | ✓ | ✓ | ✓ | ✓ | | Antigravity | ✓ | ✓ | — | — | ✓ | | Copilot | ✓ | ✓ | ✓ | ✓ | ✓ | | Windsurf | ✓ | ✓ | — | ✓ | ✓ | | OpenCode | ✓ | ✓ | ✓ | — | ✓ | | Hermes | ✓ | ✓ | ✓ | ✓ | ✓ |
* "—" indicates the agent currently does not support this extension type.
HarnessKit manages every agent's Configs, Memory, Rules, Subagents, and Ignore files from one place. Currently supporting 9 agents: Claude Code, Codex, Gemini CLI, Cursor, Antigravity, Copilot, Windsurf, OpenCode, and Hermes.
Every extension is scanned by a built-in security engine with 18 static analysis rules and receives a Trust Score (0–100), grouped into three tiers — Safe (80+), Low Risk (60–79), and Needs Review (below 60). A dedicated Audit page lets you search, filter by tier, and drill into every finding.
Discover, evaluate, and install — three marketplaces in one, each with trending lists and search:
Every listing shows its description, install count, and source. For skills, you can preview the documentation, check third-party security audit scores before installing, and install to any agent with one click — HarnessKit tracks the source so you always know where each extension came from.
The sidebar scope picker switches between Global, All scopes, or any registered project. Agents, Extensions, and Audit all filter by the active scope — per-project setups are managed independently of your global config.
Pack a curated set of skills, MCP servers, rules and memory files into a portable Kit — then deploy the whole bundle to any project with one click. Skip the setup churn every time you spin up a new project.
.hk-kit.zip to share with teammates or carry across machines. Import is one click.HarnessKit works directly with your agents' native directories instead of copying them into a managed folder — no shadow copies, no sync conflicts.