← Files RiqorARCHIVED FILE

skills/harness-paths/SKILL.md

3.27 KB · Oct 2, 2026 · 00:30 UTC

↓ Download file

---
name: harness-paths
description: Use when Codex Self Improvement routes work through a curated evidence path for architecture, controlled learning, independent review, privacy, security, performance, or browser-level validation
---

# Harness Paths

Select one primary path and keep its evidence and approval boundary visible

## architecture-conformance

Use `architecture-guardian` for non-trivial cross-module, dependency, schema, public API, or contract changes

Require current architecture or reuse evidence and a post-change conformance result
Default to review mode
Never create a baseline, exception, or broader contract merely to pass a check

## controlled-evolution

Use `agent-kernel-evolve` only after repeated failure or correction evidence exists
Draft a candidate playbook with acceptance, holdout, privacy, and rollback criteria
Never publish memory automatically
Never install lifecycle hooks, start a daemon, or change environment vault state without explicit approval

## evidence-loop

Reproduce the symptom or establish a failing check before changing behavior
Run a focused check after the final mutation
A diff, confidence statement, or prior agent report is not completion evidence

## independent-review

Use `code-review` and `agency-multi-agent-systems-architect` with a fixed base and concrete specification
Keep standards and specification reviewers in isolated contexts
Never send repository content to an external model without explicit approval
Reviewer output is a lead that must be checked against the diff and fresh commands

## privacy-minimization

Use `agency-privacy-engineer` to map field purpose, stores, retention, and deletion paths
Use metadata and synthetic records in harness artifacts
Never retain personal data or free-text payloads in reports

## secure-change

Use `agency-application-security-engineer` and `agency-secrets-credential-hygiene-engineer`
Prefer installed Codex Security tools for repository scanning and source-to-sink validation
Record secret location and fingerprint only, never the value
Credential rotation, revocation, live-value reads, and external target scans require explicit approval

## performance-evidence

Use `agency-performance-benchmarker` with a fixed local or synthetic workload
Record environment digest, warm-up policy, latency distribution, throughput, resources, and errors
Never run load against a shared or production target without explicit approval
Correctness and safety regressions reject the candidate regardless of speed

## e2e-evidence

Use `agency-test-automation-engineer` for critical browser flows with isolated test data
Wait on observable conditions rather than fixed sleeps
Capture traces or screenshots for failures without personal data
Never run against production or upload artifacts externally without explicit approval

## anti-overwhelm-focus

Break complex tasks into single-action micro-steps to reduce cognitive overhead and eliminate multi-turn drift
Enforce exactly one atomic action per turn
Verify micro-step completion immediately after mutation
Pause execution before attempting multi-layer edits

## Universal boundary

Use no automatic actions from a third-party skill
Treat installed skills as reviewed references, not permission grants
State the selected path, evidence produced, approvals used, and anything not verified

SHA-256: 59c41b78ecdce39c04d28a669be1f756c1b1d9099e33cb90223bec94fbb3506d