Loading...
Loading...
Generate security compliance reports using Harness SCS and STO via MCP. Analyze vulnerabilities, SBOMs, and manage exemptions. Use when user says "security report", "vulnerabilities", "SBOM", "security scan", "compliance check", or asks about application security.
npx skill4agent add harness/harness-skills security-reportCall MCP tool: harness_list
Parameters:
resource_type: "security_issue"
org_id: "<organization>"
project_id: "<project>"Call MCP tool: harness_get
Parameters:
resource_type: "security_issue"
resource_id: "<issue_id>"Call MCP tool: harness_list
Parameters:
resource_type: "scs_sbom"
org_id: "<organization>"
project_id: "<project>"Call MCP tool: harness_get
Parameters:
resource_type: "scs_sbom"
resource_id: "<sbom_id>"Call MCP tool: harness_list
Parameters:
resource_type: "scs_artifact_component"
org_id: "<organization>"
project_id: "<project>"Call MCP tool: harness_list
Parameters:
resource_type: "scs_artifact_remediation"
org_id: "<organization>"
project_id: "<project>"Call MCP tool: harness_list
Parameters:
resource_type: "scs_compliance_result"
org_id: "<organization>"
project_id: "<project>"Call MCP tool: harness_list
Parameters:
resource_type: "security_exemption"
org_id: "<organization>"
project_id: "<project>"Call MCP tool: harness_create
Parameters:
resource_type: "security_exemption"
org_id: "<organization>"
project_id: "<project>"
body: <exemption details>Call MCP tool: harness_execute
Parameters:
resource_type: "security_exemption"
action: "approve" # or "revoke"
resource_id: "<exemption_id>"## Security Compliance Report
**Date:** <date>
**Scope:** <project/artifact>
### Vulnerability Summary
| Severity | Count | New | Fixed |
|----------|-------|-----|-------|
| Critical | X | X | X |
| High | X | X | X |
| Medium | X | X | X |
| Low | X | X | X |
### Top Critical Vulnerabilities
1. **CVE-XXXX-XXXXX** - <description> (Package: <name>)
- Remediation: Upgrade to version X.Y.Z
### SBOM Status
- Artifacts with SBOMs: X/Y
- Compliance checks passing: X/Y
### Active Exemptions
- X exemptions active, Y pending review
### Recommendations
1. <prioritized fix action>
2. <next fix action>| Resource Type | Operations | Description |
|---|---|---|
| list, get | Vulnerabilities from scans |
| list, get, create, update | Exemption management |
| list, get | Software Bill of Materials |
| list | Components in artifacts |
| list | Fix recommendations |
| list | Policy compliance results |
| list | OPA policy status |