Verification stages your agents must pass.
A plugin is an installable bundle that registers one or more stages in your harness, ships scaffolding, and joins every agent's definition of done. Bundled plugins are discovered from the CLI; community plugins install from a path, npm package, or git URL — same command, same stage registry.
har env add-plugin <spec>Plugin docs Playwright
Browser e2e · Web appsBrowser e2e verification with frontend, API health, and accessibility smoke specs.
add-plugin playwrightstage: browser-e2eRocketSim
iOS simulator flows · iOS appsScripted iOS Simulator flows so agents verify app behavior, not just compilation.
add-plugin rocketsimstage: rocketsim-flowsKerno
Backend validation · Backend servicesDeterministic backend scenario re-runs with greybox database checks — no LLM in the loop.
add-plugin kernostage: backend-validationGitleaks
Secrets scanning · Any stackCatch leaked credentials in agent worktrees before they ever reach a branch.
add-plugin gitleaksstage: secrets-scanTrivy
Vulnerabilities & IaC · Any stackDependency CVEs and Terraform, Docker, and Kubernetes misconfigurations, caught pre-merge.
add-plugin trivystage: vuln-scanSemgrep
Static analysis (SAST) · Any stackStatic analysis on every agent worktree, with a native path to compliance evidence.
add-plugin semgrepstage: sastYour own checks
Custom stages · Community plugins · Any stackProject-specific checks stay custom stages. Reusable checks ship as your own plugin — start from os-factory/har-plugin, then install via path, npm, or git.
github:os-factory/har-pluginDocs 