How Harness orchestrates LLM security scanning | Harness Blog
Blog post from Harness
Harness Security Test Orchestration (STO) aims to make LLM-based security scanning reliable enough for continuous CI/CD use by constraining models’ otherwise variable reasoning through controlled triggering, scope, phased analysis, and standardized reporting. Built around OpenAI Codex Security with a Mythos agent plugin, it supports both full scans for audits or initial repository reviews and incremental scans for pull requests and protected-branch merges, with optional build blocking based on severity. Incremental scans retain and revalidate prior findings while limiting new vulnerability discovery to changed files, reducing costs by 58–83% and scan times by 67–72% in tests on intentionally vulnerable applications while retaining all findings identified by full scans. The workflow separates threat modeling, candidate discovery, evidence-based validation, and attack-path analysis to reduce false positives and ensure findings are relevant and reachable. Consistent report structures, validation records, format checks, and stable finding identities allow teams to compare results across scans, track fixes and newly introduced issues, and maintain a more dependable security backlog despite the nondeterministic nature of LLMs.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| LLM | 7 | 747 | 162 | 79 | -85% |
| AI Guardrails | 2 | 35 | 22 | 12 | -94% |
| Observability | 1 | 472 | 102 | 54 | -85% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.