Tools and extension types

Choose between Capabilities, Harness Plugins, MCP servers, Skills, and Content Plugins.

Choose an integration by what it provides, then select its installed key or resource ID in configuration. YAML selects executable integrations but does not install their Python code.

MechanismAddsConfigured through
CapabilityTools, instructions, hooks, settings, or lifecycle behavior on an AgentAgent capabilities
Harness PluginInstalled Harness integrationextensions/*.yaml, then an Agent/default harness_plugins selection
Environment profileProvider and Project adapter configurationextensions/*.yaml, then Environment selection
Environment Run ExtensionPer-Run Environment integrationextensions/*.yaml, then defaults.environment_run_extensions
MCP serverExternal tools from a command or remote servermcp/*.yaml or mcp/*.json, then Agent/default mcp_servers
Content PluginEditable Skill and Markdown subagent content, not a Python extensiona13n-harness-ui plugin commands

For provider-native tools and built-in search/scrape, use Native tools and Web providers.

Native search and image generation

Follow the native search and image-generation recipe; these are Agent tool choices, separate from Host Web search.

MCP servers

Configure an MCP server, then select its ID in the Agent or defaults.

MCP field reference

The complete fields are in MCP field reference.

Agent capabilities

Each Agent selection is {capability: <catalog-key>, configuration: <JSON mapping>}. Harness UI exposes its built-ins and configurable installed/native capabilities. There is no arbitrary module import field in a resource file.

Common built-in keys are dynamic_environment, documents, web, skills, working_state, user_interaction, runtime_context, handoff, compaction, and codeact. Permission and review Capabilities are intentionally absent from ordinary catalog choices; use root security.shell_review instead. Existing raw Agent selections remain compatible. Not every capability is automatically enabled.

The complete capability-specific schemas are owned by the installed Harness/native implementation, rather than flattened into Harness UI YAML. Consult the Harness capability reference and the implementation matching your installed version. a13n-harness-ui config validate checks selected keys and their configuration.

Files and shell

capabilities:
  - capability: dynamic_environment
    configuration:
      files_enabled: true
      shell_enabled: true

This enables native Environment tools, not a second local runner. Use tools on the Agent for an exact additional visibility filter and an Environment profile for execution isolation.

Shell review

Configure shell review in the selected root a13n-harness-ui.yaml, not an Agent capability picker:

security:
  shell_review:
    enable: true
    model: model-review
    risk_threshold: high

model is a configured Model resource ID, not a subagent reference or ambient provider route. The shortcut merges permissions and optional review into one ToolPermissionsCapability for shell launches, with explicit root fields taking precedence and unrelated Agent rules preserved. enable: false leaves explicit Agent policies untouched. See the complete shell-review recipe for defaults, inheritance, errors, and usage. Review is not filesystem or network isolation and is independent of the code-reviewer child.

Context management

capabilities:
  - capability: runtime_context
    configuration: {}
  - capability: handoff
    configuration: {}
  - capability: compaction
    configuration: {}

Normally configure model_characteristics on the Model so reminder and compaction defaults stay aligned. Advanced explicit settings include runtime_context.configuration.context_window_tokens, handoff.configuration.summary_reminder_tokens, and compaction.configuration.trigger_tokens; explicit values take precedence over derived values.

Tasks, questions, and CodeAct

Task and note tools are available by default through native working state, including bounded note-context injection. working_state accepts native configuration such as notes_enabled: false to disable notes. F2 displays committed task facts, not a separate CLI checklist store.

Root tools.enable_ask_user_question gates ask_user_question; tools.enable_codeact gates CodeAct. Both switches also gate explicitly authored capability selections. CodeAct also exposes store, load, and forget for explicit JSON values saved with the Harness continuation; only stored key names are projected into context. Agent capability configuration accepts max_state_bytes and max_state_entries to bound this state. Its run_code and run_program execute restricted Python; host effects use eligible tools and their existing policy, not unrestricted Python filesystem or network access. See the root reference for defaults and the decision guide for question timeouts.

Skills

See Skills and Content Plugins for explicit and automatic source precedence, the built-in offline configuration Skill, file access, and catalog capture. Selecting Skills adds knowledge discovery; it does not grant execution permissions.

Content Plugins

See Content Plugin installation, destructive uninstall behavior, and the complete repository format. These are editable content bundles, not installed Python Harness Plugins.

Harness Plugin and Run Extension files

A Harness Plugin resource selects an installed factory. Replace this illustrative key and configuration with those documented by your integration:

schema_version: "1"
kind: harness_plugin
id: plugin-memory
name: Memory integration
plugin_key: vendor.memory
configuration: {}

Save it under extensions/, then select harness_plugins: [plugin-memory] in the Agent or root defaults. Unknown/uninstalled keys fail validation; writing the file is not installation.

Resource kindComplete fields beyond shared schema_version, kind, id, name
harness_plugin (plugin- ID)Required plugin_key; configuration defaults to {}
environment_run_extension (extension- ID)Required extension_key; configuration defaults to {}
environment_profile (environment- ID)Required provider_key and adapter_key; provider_configuration and adapter_configuration default to {}

Run Extensions are selected through root defaults.environment_run_extensions. Provider/adapter and extension-specific configuration belongs to the installed implementation, with credential references rather than literal secret fields. See custom Environment profiles before selecting a provider.

On this page