finds.dev← search

// the find

ruvnet/metaharness

★ 686 · TypeScript · MIT · updated Oct 2026

🛠️ The meta-harness for AI agents — scaffold your own focused, branded agent harness with its own npx CLI, MCP server, memory, learning loop, and witness-signed releases. Works with Claude Code, Codex, pi.dev, Hermes, OpenClaw, and RVM (hardware-isolated sandbox).

MetaHarness is a generator. Point it at a GitHub repo, or start blank, and it emits an npm-publishable agent harness with its own CLI, MCP server, scoped memory, governance policy, and Ed25519-signed release manifest for Claude Code, Codex, pi.dev, Hermes, OpenClaw, RVM, and others. It suits maintainers who want a branded agent for their team and are willing to own and trim the generated output.

MCP is default-deny: no network, shell, or file-write grants, a 30s timeout, and an audit log by default. The `harness mcp-scan` static check exits 1 on any high-severity finding, which is the right default for tool access an agent will actually use. Repo analysis is deterministic and says so: `analyze-repo` and `genome` never execute the target, and inferred build and test commands are labelled `trust: inferred · execution: disabled` instead of being presented as fact. The release side is more serious than most projects this size bother with, with an Ed25519 witness manifest, an SPDX SBOM, npm provenance through GCP workload identity, and a generated `harness validate` gate. The shared primitives live in one Rust crate built to WASM and NAPI-RS, a sensible boundary if the kernel stays small.

The scope is already sprawling. Ten hosts, nineteen vertical templates, a Rust kernel, Darwin self-evolution, field memory, weight-EFT distillation, an ARC-AGI-3 controller, and 220 ADRs all live in one repo. Each host adapter has to track its vendor's config format, and the README's own status section says the doc and claim reconciliation (ADR-042) is still in progress. Several headline numbers are self-reported and carry caveats that sit below the fold. The 55.6% SWE-bench Verified figure uses an estimated cost, and the AVO-class claim is explicitly blocked on a gate that has not run yet. Read the linked ADRs before quoting any of them. The advanced parts are opt-in and fail closed by design. Field memory will not open storage without an absolute path, a compatible adapter, and a deployment-backed principal verifier, so the learning loop in the pitch is mostly scaffolding until a team builds its own identity layer. The product is the generated output, which means trimming and owning it falls on the user. The README says to delete what you don't need but does not say which generated pieces can be removed without breaking `harness doctor` or `harness validate`.

View on GitHub → Homepage ↗

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →