← Files RiqorARCHIVED FILE
skills/harness-paths/SKILL.md
3.27 KB · Oct 5, 2026 · 18:30 UTC
--- name: harness-paths description: Use when Codex Self Improvement routes work through a curated evidence path for architecture, controlled learning, independent review, privacy, security, performance, or browser-level validation --- # Harness Paths Select one primary path and keep its evidence and approval boundary visible ## architecture-conformance Use `architecture-guardian` for non-trivial cross-module, dependency, schema, public API, or contract changes Require current architecture or reuse evidence and a post-change conformance result Default to review mode Never create a baseline, exception, or broader contract merely to pass a check ## controlled-evolution Use `agent-kernel-evolve` only after repeated failure or correction evidence exists Draft a candidate playbook with acceptance, holdout, privacy, and rollback criteria Never publish memory automatically Never install lifecycle hooks, start a daemon, or change environment vault state without explicit approval ## evidence-loop Reproduce the symptom or establish a failing check before changing behavior Run a focused check after the final mutation A diff, confidence statement, or prior agent report is not completion evidence ## independent-review Use `code-review` and `agency-multi-agent-systems-architect` with a fixed base and concrete specification Keep standards and specification reviewers in isolated contexts Never send repository content to an external model without explicit approval Reviewer output is a lead that must be checked against the diff and fresh commands ## privacy-minimization Use `agency-privacy-engineer` to map field purpose, stores, retention, and deletion paths Use metadata and synthetic records in harness artifacts Never retain personal data or free-text payloads in reports ## secure-change Use `agency-application-security-engineer` and `agency-secrets-credential-hygiene-engineer` Prefer installed Codex Security tools for repository scanning and source-to-sink validation Record secret location and fingerprint only, never the value Credential rotation, revocation, live-value reads, and external target scans require explicit approval ## performance-evidence Use `agency-performance-benchmarker` with a fixed local or synthetic workload Record environment digest, warm-up policy, latency distribution, throughput, resources, and errors Never run load against a shared or production target without explicit approval Correctness and safety regressions reject the candidate regardless of speed ## e2e-evidence Use `agency-test-automation-engineer` for critical browser flows with isolated test data Wait on observable conditions rather than fixed sleeps Capture traces or screenshots for failures without personal data Never run against production or upload artifacts externally without explicit approval ## anti-overwhelm-focus Break complex tasks into single-action micro-steps to reduce cognitive overhead and eliminate multi-turn drift Enforce exactly one atomic action per turn Verify micro-step completion immediately after mutation Pause execution before attempting multi-layer edits ## Universal boundary Use no automatic actions from a third-party skill Treat installed skills as reviewed references, not permission grants State the selected path, evidence produced, approvals used, and anything not verified
SHA-256: 59c41b78ecdce39c04d28a669be1f756c1b1d9099e33cb90223bec94fbb3506d