Project releases
MetaHarness 0.4.17 ships a batch of security fixes, including the .env guard finding
MetaHarness 0.4.17, released September 26, closes a set of security and correctness findings. One is the overnight-review finding filed as issue #326: the MCP scan treated a deny rule for the harmless .env.example file as protecting the real .env secrets file. That fix is now merged and published.
GitHub activity: · Published:
What this is about
MetaHarness generates a custom agent harness from a repository: a CLI with your name on it, tuned to that codebase. Harnesses it generates can expose tools over MCP, and it ships a scanner, mcp-scan, that checks a harness for risky settings the way npm audit checks dependencies.
One of those checks asks whether the real .env file, where secrets usually live, is protected by a deny rule. That check had a flaw, and on September 18 an automated overnight review filed it as issue #326. Last week this site listed it as a watch item only, because nothing had shipped. It has now shipped.
What changed
The scanner and the threat-model command both used an unanchored pattern to recognise a .env deny rule. A rule covering only .env.example, a harmless template, satisfied it. The result was a false clean verdict while the real .env was readable through a broad read grant.
Commit f092f20c, merged as pull request #327 and closing the issue on September 26, replaces both copies with a single anchored helper used by both commands. The commit records that an independent adversarial reviewer found a remaining gap in the first attempt, where a rule for secrets.env still counted, and that it was closed in a second round. Tests for the harness generator went from 572 to 575 passing out of 577.
The same day, release v0.4.17 published it alongside other fixes listed in its notes:
- Security: atomic-write path traversal and host-adapter injection (#300), the .env guard anchoring (#327), MCP detection in settings.json (#298), a Grade A score no longer hiding a High MCP risk (#337), reward-hack monitoring that now scans tool responses (#293).
- Correctness: promotion-rule lockouts (#307, #320), a flywheel graph crash (#341), and host adapters keeping their autonomous setting (#332).
- Published packages: metaharness 0.4.17, @metaharness/darwin 0.10.3, flywheel 0.1.12 and patch releases of nine host adapters.
Get started
Prerequisites: Node.js and a terminal. Listing the templates does not create any files.
npx metaharness --list
Expected result: the CLI prints its quick-start templates. To generate a harness and see its commands:
npx metaharness my-bot --template vertical:coding --host claude-code
cd my-bot && npx . --help
Inside a generated harness, the README documents harness mcp-scan <path> for the static scan and harness threat-model for a review artifact. The scan exits with code 1 on any High finding.
MCP: harnesses can emit an MCP server in off, local (stdio) or remote (HTTPS with auth) mode, default-deny. There is no single hosted MetaHarness MCP endpoint to add. No npx skills package is documented. A browser Studio is linked from the README.
Commands here were read from the release notes and repository documentation at the pinned reference; they were not executed as part of writing this article.
Use it today
Practical case: a reviewer wants a gate that fails a pull request when an agent harness can read secrets. Input is the harness directory. The workflow runs mcp-scan in CI. Output is a list of findings and a non-zero exit on any High, which blocks the merge.
Reader acceptance test: in a scratch harness, add a settings deny rule that covers only .env.example, alongside a broad read grant. On 0.4.17 the scan should report the real .env as unguarded. On an older version it reported the harness as clean.
Push it further
Experimental commentary. This is a readable example of the overnight review loop producing something that actually merges: a finding, an evaluated fix, an adversarial second look and a release. Last week's issue text noted that none of the preceding sixteen overnight pull requests had merged, so one landing is worth noting without overstating it.
Limitation: mcp-scan is static only. It reads configuration, it does not observe a running agent. Falsifiable test: count how many overnight review issues opened in September have a merged fix by the end of October. If the number stays near one, the loop is still mostly producing reports rather than changes.