HarnessDelta 0.1.6

HarnessDelta reviews semantic changes to coding-agent configuration before they land. It examines Git objects and working-tree files locally for newly executable hooks or MCP servers, provably broadened Claude Code allow rules, newly broadened Codex allow prefixes, weakened sandbox or approval policy, deleted guardrail-bearing configuration, changed instruction scope, plugin or skill changes, hidden controls, and likely embedded credentials. Reports use relative paths, counts, hashes, and redacted findings rather than repository roots, configuration contents, commands, endpoints, permission values, or possible credentials.

Tags security software-development version-control javascript linux developers system-administrators artificial-intelligence static-analysis claud
License MITL
State stable

Recent Releases

0.1.624 Jul 2026 20:36 security: Version 0.1.6 adds redacted high-severity findings for provably broader Claude Code shell-prefix and same-anchor Read/Edit allow rules, with bounded comparison and conservative generic fallback for ambiguous forms. Version 0.1.5 adds semantic checks for broadened Codex allow prefixes and prompt/forbidden-to-allow transitions. Version 0.1.4 detects deleted Claude deny rules and executable definitions, removed Claude/Codex MCP definitions, and removed Codex approval or sandbox controls.
0.1.321 Jul 2026 19:52 security: Reject symlinks, non-regular files, invalid UTF-8, and inputs above 2 MiB