
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
@harness-forge/cli
Advanced tools
Harness Forge: modular agentic AI workspace installer, catalog, and workflow runtime.
Deterministic AI workspace bootstrapping for Codex, Claude Code, and adjacent agentic runtimes.
Install skills, knowledge packs, workflows, validation gates, and repo intelligence into a real repository — without mixing package content with workspace state.
Quick Start · Why Harness Forge · Supported Targets · Commands · Credits
[!TIP] First time here? Run
npx @harness-forge/clifrom the repository you want to equip. The CLI now acts like a guided front door for onboarding and setup.
Harness Forge is a packaging-friendly agentic workspace kit built for teams that want repeatable AI runtime setup instead of ad hoc prompting.
It helps you:
| Area | What Harness Forge does |
|---|---|
| 🧠 Agent runtime | Creates predictable runtime surfaces like AGENTS.md, .agents/skills/, .codex/, .claude/, and the hidden canonical .hforge/ layer |
| 🧩 Composition | Lets you combine targets, profiles, languages, frameworks, and capability bundles through a single install flow |
| 🔎 Repo intelligence | Recommends packs and guidance based on the actual repo rather than generic setup assumptions |
| 🛡️ Validation | Ships doctor, audit, review, diff-install, and release-grade checks so handoff quality stays measurable |
| 🔁 Lifecycle | Supports bootstrap, refresh, upgrade, sync, prune, export, and flow recovery workflows over time |
npx @harness-forge/cli
Best for first-time operators who want:
quick, recommended, advanced)npx @harness-forge/cli bootstrap --root . --yes
This path is ideal when you want Harness Forge to:
hforge status --root . --json
hforge doctor --root . --json
hforge audit --root . --json
flowchart LR
A[Repository] --> B[npx @harness-forge/cli]
B --> C[Guided onboarding or bootstrap]
C --> D[Visible runtime bridges]
C --> E[Hidden canonical .hforge layer]
D --> F[.agents/skills and target runtimes]
E --> G[Rules, knowledge, templates, runtime state]
G --> H[status / doctor / audit / review]
quick, recommended, or advanced.status, doctor, and audit.| Surface | Purpose |
|---|---|
.agents/skills/ | Thin, discoverable wrappers for agent runtimes |
.hforge/library/ | Hidden canonical skills, rules, templates, and knowledge packs |
.hforge/runtime/ | Shared runtime state, repo intelligence, findings, and decision indexes |
.specify/ | Structured spec -> plan -> tasks -> implement workflow helpers |
.codex/ / .claude/ | Target-specific runtime payloads and bridge files |
.hforge/generated/ | Launchers, generated catalogs, and machine-readable runtime artifacts |
Harness Forge is strongest with Codex and Claude Code today.
| Target | Runtime support | Hooks | Flow recovery | Best fit |
|---|---|---|---|---|
| Codex | First-class | Partial, documentation-driven | First-class | Default choice for full install, recommendation, maintenance, and flow support |
| Claude Code | First-class | First-class | First-class | Best choice when native hook support matters |
| Cursor | Partial | Partial | Partial | Best for consuming docs, manifests, and recommendation output |
| OpenCode | Partial | Partial | Partial | Best for docs, manifests, and recommendation output |
[!NOTE] Canonical support truth should live in
manifests/catalog/harness-capability-matrix.json. Usedocs/target-support-matrix.mdas the operator-facing summary.
| Mode | Entry point | When to use it |
|---|---|---|
| Guided onboarding | npx @harness-forge/cli | First-time setup, interactive review, and a polished onboarding experience |
| Direct setup | hforge init --root <repo> --agent codex --yes | CI, scripts, automation, or operators who already know the desired target |
| Bootstrap | npx @harness-forge/cli bootstrap --root . --yes | Auto-detect runtimes and install a sensible target stack in one pass |
| Catalog expansion | hforge catalog add ... | Add languages, frameworks, or bundles as the repository evolves |
node dist/cli/index.js install \
--target codex \
--profile core \
--lang typescript \
--framework react \
--with workflow-quality \
--root /path/to/your/workspace \
--yes
node dist/cli/index.js install \
--target claude-code \
--profile core \
--lang python \
--framework fastapi \
--with workflow-quality \
--root /path/to/your/workspace \
--yes
.hforge/agent-manifest.json| Requirement | Notes |
|---|---|
| Node.js 22+ | Required to build and run the CLI |
| npm | Used for install, build, validation, and bootstrap flows |
| A target repository | The workspace that should receive the installed agent surfaces |
| PowerShell | Needed for the shipped PowerShell validation bundle on Windows and cross-platform PowerShell setups |
Run these after installation:
npx @harness-forge/cli shell setup --yes
hforge status --root /path/to/your/workspace --json
hforge refresh --root /path/to/your/workspace --json
hforge doctor --root /path/to/your/workspace --json
hforge audit --root /path/to/your/workspace --json
hforge review --root /path/to/your/workspace --json
| Check | Signal |
|---|---|
| Install state | Installed targets, bundles, timestamps, and file writes are present |
| Agent command catalog | .hforge/generated/agent-command-catalog.json exists |
| Custom-agent manifest | .hforge/agent-manifest.json exists |
| Skill discovery layer | .agents/skills/ is present |
| Canonical AI layer | .hforge/library/skills/, rules/, and knowledge/ are populated |
| Runtime state | .hforge/runtime/index.json and related findings/decision files exist |
| Target runtime | .codex/ or .claude/ exists in the workspace |
| Goal | Command |
|---|---|
| Initialize the hidden runtime in a repo | npx @harness-forge/cli init --root /path/to/your/workspace --json |
Enable bare hforge on PATH | npx @harness-forge/cli shell setup --yes |
| Auto-detect targets and bootstrap | npx @harness-forge/cli bootstrap --root /path/to/your/workspace --yes |
| Inspect the catalog | hforge catalog --json |
| List commands agents can use | hforge commands --json |
| Inspect what is installed | hforge status --root /path/to/your/workspace --json |
| Refresh runtime summaries | hforge refresh --root /path/to/your/workspace --json |
| Summarize runtime health | hforge review --root /path/to/your/workspace --json |
| Export runtime state | hforge export --root /path/to/your/workspace --json |
| Generate repo-aware recommendations | hforge recommend /path/to/your/workspace --json |
| Build a repo map | hforge cartograph /path/to/your/workspace --json |
| Inspect target capabilities | hforge target inspect codex --json |
| Validate templates | hforge template validate --json |
| Compare install state vs workspace | hforge diff-install --root /path/to/your/workspace --json |
Harness Forge can inspect a repository and recommend packs, profiles, skills, and missing validation surfaces with evidence.
hforge recommend tests/fixtures/benchmarks/typescript-web-app --json
hforge cartograph tests/fixtures/benchmarks/monorepo --json
hforge classify-boundaries tests/fixtures/benchmarks/monorepo --json
hforge synthesize-instructions tests/fixtures/benchmarks/monorepo --target codex --json
npm run validate:local
npm run release:dry-run
npm run build
npm run validate:local
npm run smoke:cli
npm run commands:catalog
npm run bootstrap:current
npm run recommend:current
npm run cartograph:current
npm run instructions:codex
npm run target:codex
npm run target:claude-code
npm run target:opencode
npm run validate:release
npm run validate:compatibility
npm run validate:skill-depth
npm run validate:framework-coverage
npm run validate:doc-command-alignment
npm run validate:runtime-consistency
npm run observability:summary
npm run knowledge:coverage
npm run knowledge:drift
[!IMPORTANT]
npm run validate:releaseshould be treated as the front-door release gate for shipped changes.
| Folder | Purpose |
|---|---|
.agents/ | Auto-discoverable skill wrappers and target-facing bridge surfaces |
.hforge/ | Hidden canonical AI layer, runtime state, templates, observability, and generated outputs |
.specify/ | Structured delivery flow assets (spec -> plan -> tasks -> implement) |
dist/ | Built CLI output from the TypeScript source tree |
docs/ | Front-door documentation, catalogs, target guidance, and lifecycle docs |
knowledge-bases/ | Source-authored seeded and structured knowledge packs |
manifests/ | Catalogs, bundles, profiles, target definitions, and package metadata |
scripts/ | CI, runtime, knowledge, intelligence, validation, and maintenance scripts |
skills/ | Source-authored canonical packaged skills and reference packs |
src/ | TypeScript implementation of the CLI and supporting layers |
targets/ | Target adapters and runtime payloads for supported harnesses |
templates/ | Reusable task, instruction, and workflow templates |
tests/ | Contract, integration, and fixture coverage |
When integrating a custom agent, start here:
AGENTS.md.hforge/agent-manifest.json.hforge/runtime/index.json.hforge/generated/agent-command-catalog.json.agents/skills/<skill>/SKILL.md.hforge/library/skills/<skill>/SKILL.mdHarness Forge was inspired by github/spec-kit.
A lot of the thinking around structured specification flow, disciplined planning, and operator-friendly delivery benefited from that inspiration. Big credit to the GitHub team for helping shape a cleaner workflow model.
This project is licensed under GPL-3.0. See LICENSE.md.
Built for teams who want their agent workflows to be repeatable, inspectable, and release-safe.
FAQs
Harness Forge: modular agentic AI workspace installer, catalog, and workflow runtime.
The npm package @harness-forge/cli receives a total of 44 weekly downloads. As such, @harness-forge/cli popularity was classified as not popular.
We found that @harness-forge/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.