verify

Verificar cambios de harness de extremo a extremo sin docker — ejecutar la CLI real fijada contra un servidor stub que captura encabezados con el entorno exacto resolve_auth_env()…

npx skills add https://github.com/anthropics/defending-code-reference-harness --skill verify

Verifying harness changes on a docker-less host

The pipeline's real surface is the in-container claude -p process and its outbound API requests. Without docker, drive the same pinned CLI binary directly with the env dict the harness would inject via docker -e.

Recipe

  1. Get the pinned CLI (version from harness/agent_image.py:CLAUDE_CODE_VERSION): npm install --no-save @anthropic-ai/claude-code@<pin> in a temp dir → binary at node_modules/@anthropic-ai/claude-code/bin/claude.exe (the .exe name is the real native-binary entry on Linux too, filled in by the package's postinstall — not a Windows leftover).
  2. Stub API server: a tiny HTTP server that appends each request's headers to a JSONL file and returns a 400 invalid_request_error (non-retryable, so the CLI exits fast; exit=1 is expected).
  3. Build the agent env exactly as the pipeline does: python3 -c "from harness.auth import resolve_auth_env; ..." and dump to an export-lines file with shlex.quote (values contain newlines — NEVER pass via env $(...), word-splitting mangles them; source the file).
  4. Emulate the container env: unset ANTHROPIC_CUSTOM_HEADERS (and any other ambient var not in the resolved dict) before sourcing — a Claude Code session in this repo injects .claude/settings.json env into shells, which containers never see.
  5. Run: ANTHROPIC_BASE_URL=http://127.0.0.1:<port> CLAUDECODE= IS_SANDBOX=1 timeout 30 <cli> -p hi --model claude-sonnet-4-5 --max-turns 1, then read the captured JSONL.

Gotchas

  • Unit tests in tests/test_patch.py / tests/test_patch_grade.py need docker and fail on docker-less hosts — pre-existing, not your change.
  • The docker -e injection leg itself can't be exercised without docker; it's the same mechanism that carries ANTHROPIC_API_KEY in production.
  • For the interactive-skills surface, copy .claude/settings.json into a fresh temp dir and run the host claude from there (with ambient ANTHROPIC_CUSTOM_HEADERS unset so settings.json is the only source).

Más skills de anthropic

access
anthropic
Gestiona el acceso a canales de Discord: aprueba emparejamientos, edita listas permitidas, configura políticas de DM/grupo. Úsalo cuando el usuario pida emparejar, aprobar a alguien, verificar quién está permitido…
official
session-report
anthropic
Generar un informe HTML explorable del uso de la sesión de Claude Code (tokens, caché, subagentes, habilidades, prompts costosos) a partir de las transcripciones de ~/.claude/projects.
official
build-mcp-server
anthropic
Esta habilidad debe usarse cuando el usuario solicite "construir un servidor MCP", "crear un MCP", "hacer una integración MCP", "envolver una API para Claude", "exponer herramientas a…
official
cookbook-audit
anthropic
Auditar un cuaderno de Anthropic Cookbook basado en una rúbrica. Úsalo siempre que se solicite una revisión o auditoría de un cuaderno.
official
handle-complaint
anthropic
Gestiona una queja entrante de cliente de principio a fin: extrae el contexto, redacta una respuesta y sugiere una solución operativa. Acepta un correo electrónico o ID de ticket opcional…
official
use-case-triage
anthropic
Determinar rápidamente si una actividad de procesamiento necesita una PIA, una DPIA obligatoria del GDPR, o puede continuar — detecta conflictos con la política de privacidad y dirige al…
official
board-minutes
anthropic
Redacta actas de reuniones de la junta o comité en el formato de su organización. Detecta automáticamente las próximas reuniones de la junta y comités desde su calendario, solicita la agenda y…
official
renewal-tracker
anthropic
Muestra los contratos con fechas límite de cancelación próximas y advierte antes de que se cierren las ventanas de notificación, trabajando desde un registro de renovaciones mantenido. Úsalo cuando el usuario pregunte…
official