# TrustHarness

> TrustHarness — ofirtro-trustharness. Use this tool when you need to test the security of AI agents that interact with tools, as it simulates potentially vulnerable environments and evaluates their behavior against security invariants. TrustHarness takes in AI agent configurations and tool interactions as input, and outputs detailed security test results, identifying potential issues such as data leaks or unauthorized access. It is ideal for use cases where deterministic security testing is crucial, such as in high-stakes or sensitive applications.

Canonical page: https://skillsregistry.net/skills/ofirtro-trustharness  
JSON: https://api.skillsregistry.net/v1/skills/ofirtro-trustharness

## Description

Enables deterministic security testing of AI agents that use tools by serving synthetic MCP environments with poisoned data, fake secrets, and privileged actions. Records agent tool calls and evaluates security invariants (e.g., canary leaks, forbidden access, approval binding) without an LLM judge or real systems.

## Trust

- **Trust score (0–1):** 0.69
- **Verification tier:** scanned
- **Last scanned:** 2026-08-29

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** ai-ml
- **Updated:** 2026-08-29

## Source

- **Source listing:** [Glama](https://glama.ai/mcp/servers/lo1pe0he2h)
- **Repository:** <https://github.com/ofirtro/trustharness>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "ofirtro-trustharness"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/ofirtro-trustharness` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/ofirtro-trustharness/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
