
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
@harness-forge/cli
Advanced tools
Harness Forge: modular agentic AI workspace installer, catalog, and workflow runtime.
Your AI coding agent is only as good as its harness.
One command to scan, equip, and continuously improve any AI coding agent in your repository.
π Get Started β’ π Living Loop β’ π Dashboard β’ β¨οΈ Commands β’ π‘ Scenarios β’ π― Targets β’ β FAQ
π Scans & EquipsYour AI agent gets your repo's languages, frameworks, and patterns from the first prompt |
π Self-ImprovesA closed feedback loop learns what works, tunes itself, and gets smarter every session |
π Full VisibilityReal-time dashboard shows every decision, token spend, and compaction β no black boxes |
| Without Harness Forge | With Harness Forge | |
|---|---|---|
| π§ Context | Agent guesses at project structure | Agent knows your languages, frameworks, boundaries |
| β‘ Performance | Starts fresh every session | Self-improves over time via the Living Loop |
| π Visibility | Black box β no idea what the agent decided | Real-time dashboard with 20 live panels |
| π° Cost | Wasted tokens on retries and wrong paths | Compaction + auto-tuning saves 20-40% |
| π€ Portability | Stuck on one machine, one setup | Export & import learned patterns as .hfb bundles |
Most tools configure once and forget. Harness Forge keeps learning.
ββββββββββββ ββββββββββββ ββββββββββββ ββββββββββββ ββββββββββββ
β π β β π§ β β β‘ β β π€ β β π₯ β
β OBSERVE βββββΆβ LEARN βββββΆβ ADAPT βββββΆβ SHARE βββββΆβ IMPORT β
β β β β β β β β β β
β Tracks β β Finds β β Auto- β β Export β β Bootstrapβ
β sessions β β patterns β β tunes β β bundles β β anywhere β
ββββββββββββ ββββββββββββ ββββββββββββ ββββββββββββ ββββββββββββ
β² β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
π Day 1 β You install
Scans your repo. Installs skills, rules, knowledge packs. Default settings. Everything works out of the box. |
π Day 3 β After ~10 sessions
|
π Day 5 β Share with your team
|
π Ongoing β Dashboard shows it all
Loop health ring, effectiveness scores, pattern list, tuning log β live in your browser. |
The more you use it, the better it gets. After ~10 sessions, Harness Forge has learned your repo's patterns and tuned itself for optimal performance. No manual configuration needed.
hforge dashboardβ see everything, live in your browser.
π Loop RingLive status of each loop stage with health score |
π EffectivenessSession score trend β are things getting better? |
π§ InsightsDiscovered patterns with confidence bars |
β‘ Tuning LogPolicy changes with one-click revert |
| Panel | What it shows |
|---|---|
| π’ KPI Cards | Total events, tokens, enforcement level, budget gauge |
| π Event Timeline | Scatter plot of all events over time, color-coded by category |
| πΎ Memory Pressure | Token usage line chart with threshold marklines |
| π Budget Breakdown | Donut chart of budget allocation (hot-path, output, tools, safety) |
| π Live Event Feed | Searchable, expandable table of every harness decision |
| π€ Subagent Briefs | Delegated tasks, their context, and outcomes |
| π Brief Metrics | Subagent activity summary and success rates |
| π Suppression Gauge | How many duplicate context items were removed |
| πͺ Expansion Gate | History access requests β granted vs denied |
| βοΈ Config Editor | Edit memory-policy, context-budget, load-order live |
| π Loop Health Ring | Self-improvement cycle status with stage counts |
| π Effectiveness Trend | Session score sparkline (last 20 sessions) |
| π§ Insights Panel | Discovered patterns with confidence and "NEW" badges |
| β‘ Tuning Log | Policy changes with before/after and revert button |
| π Event Distribution | Bar chart of top event types |
| β±οΈ Event Rate | Events per minute over time |
| πΊοΈ Event Heatmap | Category Γ time heatmap |
| π° Tokens Saved | Running counter of tokens saved by compaction |
| π Profile Distribution | Output profile selection breakdown |
| βΉοΈ Session Info | Session ID, uptime, version, connection status |
π Desktop notifications for critical events β budget exceeded, memory rotation, tuning applied, pattern discovered.
π’ Multi-project support β switch between projects in one dashboard. Your project list is saved in the browser.
The CLI walks you through:
Then make
|
One-liner for CI / scripts:
Verify everything is healthy:
|
Commands organized by when you use them β not alphabetically.
| Command | What it does | |
|---|---|---|
| π‘ | hforge next | Recommends the single most useful action right now |
| π₯ | hforge doctor | Full health check with evidence |
| π | hforge refresh | Regenerate runtime after code changes |
| π | hforge status | Review what's installed |
| Command | What it does | |
|---|---|---|
| π | hforge dashboard | Open the real-time browser dashboard |
| π | hforge score | Show recent session effectiveness scores |
| π§ | hforge insights | Browse learned patterns with confidence |
| β‘ | hforge adapt | View/manage auto-tunings |
| π | hforge trace | View recent session traces |
| π | hforge loop | Living Loop health summary |
| Command | What it does | |
|---|---|---|
| π¦ | hforge export --bundle team.hfb | Export tuned harness as portable bundle |
| π₯ | hforge import team.hfb | Bootstrap from a shared bundle |
| π§ | hforge update | Update harness to latest version in place |
| π¬ | hforge audit | Verify install integrity |
| π | hforge diff-install | Check what drifted since last install |
| π§Ή | hforge prune | Clean up unused artifacts |
| Command | What it does | |
|---|---|---|
| πΊοΈ | hforge cartograph | Map repo structure and boundaries |
| π | hforge recommend | Evidence-backed setup recommendations |
| 𧬠| hforge recursive plan "..." | Structured recursive analysis for hard problems |
| π― | hforge target compare codex claude-code | Side-by-side target comparison |
π "Just cloned a repo, want AI help"
|
π€ "I use both Codex and Claude Code"
Both agents share |
π "Coming back to a project after a break"
|
π₯ "Standardize AI setup across my team"
|
|
Use both together β they share the same
|
TypeScript, Python, Java, Go, Kotlin, Rust, C++, .NET, PHP, Perl, Swift, Shell, Lua, PowerShell
React, Next.js, Vite, Express, FastAPI, Django, ASP.NET Core, Spring Boot, Laravel, Symfony, Gin, Ktor
Language engineering, workflow orchestration, operational helpers, and specialized skills like incident triage, dependency upgrades, API contract review, database migration review, release readiness, and token-budget-optimizer for context-aware compaction.
Your Repo
β
βββ AGENTS.md β AI agents read this first
βββ .agents/skills/ β Discoverable skills
βββ .codex/ or .claude/ β Target-specific config
βββ .hforge/ β Hidden canonical runtime
βββ library/ β Skills, rules, knowledge packs
βββ runtime/ β State, indexes, traces, insights
βββ generated/ β Command catalog, launchers
βββ templates/ β Workflow templates
Visible bridges where AI agents need discovery. Hidden canonical layer where runtime content stays authoritative.
No. npx @harness-forge/cli runs directly. For the shorter hforge command, run hforge shell setup --yes once.
Never. Harness Forge only creates its own files (AGENTS.md, .agents/, .hforge/, .codex/, .claude/). Your application code is untouched.
Yes. Add --yes for non-interactive and --json for machine-readable output:
hforge init --root . --agent codex --setup-profile recommended --yes
hforge doctor --root . --json
Delete: .hforge/, .agents/, .codex/, .claude/, AGENTS.md. Your project is back to normal.
No. Everything stays local under .hforge/. Nothing is ever sent to the internet. Inspect, delete, or back up anytime.
Node.js 22 or newer. Check with node --version.
See CONTRIBUTING.md for development setup and guidelines.
Harness Forge was inspired by github/spec-kit. Credit to the GitHub team for shaping cleaner workflow models.
GPL-3.0 β see LICENSE.
Your AI agent deserves a better harness.
npx @harness-forge/cli
FAQs
Harness Forge: modular agentic AI workspace installer, catalog, and workflow runtime.
The npm package @harness-forge/cli receives a total of 36 weekly downloads. As such, @harness-forge/cli popularity was classified as not popular.
We found that @harness-forge/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago.Β It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.