harness-code-security-mcp
v0.2.0
Published
Qwiet / Harness SAST & SCA MCP server (stdio)
Maintainers
Readme
Harness Code Security MCP
harness-code-security-mcp is the Qwiet AI by Harness MCP server for agent-driven security workflows:
- run
sl analyze - list and triage findings
- fetch data flows
- request and apply Qwiet AutoFix recommendations
- look up package CVEs
The npm package ships a bundled stdio MCP runtime and a small launcher. It is a proprietary runtime distribution, not a source-code distribution. The launcher is the public harness-code-security-mcp binary; it checks for a newer npm-published runtime at startup at most once per day and falls back to the bundled runtime if the update check fails.
Install
Claude Code (recommended)
In your terminal (or ask Claude to run this in Bash from inside a session):
claude mcp add harness-code-security-mcp -- npx -y harness-code-security-mcpStdio is the default transport — --transport stdio is optional. No env block is required.
After adding, run /mcp to confirm the server is connected, or start a new session if tools are not listed yet. Inside Claude Code, tools appear as mcp__harness-code-security-mcp__<tool> (for example mcp__harness-code-security-mcp__sl_whoami).
From inside Claude Code: run the same claude mcp add … command via Bash. If argument parsing is awkward (the -- separator), use JSON instead:
claude mcp add-json harness-code-security-mcp '{"type":"stdio","command":"npx","args":["-y","harness-code-security-mcp"]}'Share with your team (writes project .mcp.json):
claude mcp add --scope project harness-code-security-mcp -- npx -y harness-code-security-mcpWindows:
claude mcp add harness-code-security-mcp -- cmd /c npx -y harness-code-security-mcpAlready installed globally?
npm install -g harness-code-security-mcp
claude mcp add harness-code-security-mcp -- harness-code-security-mcpCursor and other agents
npm install -g harness-code-security-mcpThen configure your agent MCP server to run:
{
"mcpServers": {
"harness-code-security-mcp": {
"command": "harness-code-security-mcp"
}
}
}No env block is required. The server defaults to API host app.shiftleft.io and config directory ~/.shiftleft.
Optional environment overrides
| Variable | Default | When to override |
| --- | --- | --- |
| QWIET_API_HOST | app.shiftleft.io | Staging or self-hosted API |
| SL_HOME | ~/.shiftleft | Custom ShiftLeft config directory |
| WORKSPACE_FOLDER | Agent working directory | AutoFix path resolution when cwd is not the repo root |
Credentials
Run sl auth first so ~/.shiftleft/config.json contains orgId and accessToken.
The MCP server can install or update the Qwiet CLI under ~/.shiftleft through the sl_ensure_cli tool. Code analysis runs locally through sl analyze; scan results upload to Qwiet AI by Harness.
Launcher Controls
harness-code-security-mcp --no-auto-updatedisables startup update checks.harness-code-security-mcp --version-pin x.y.zruns a specific npm package version from the launcher's local cache.harness-code-security-mcp --debugprints launcher diagnostics to stderr.
The launcher never writes progress to stdout during normal MCP operation; stdout is reserved for MCP JSON-RPC.
