Home / Companies / Harness / Blog / Post Details
Content Deep Dive

How Harness orchestrates LLM security scanning | Harness Blog

Blog post from Harness

Post Details
Company
Date Published
Author
Renny Shen
Word Count
2,140
Company Posts That Month
29
Language
English
Hacker News Points
-
Post removed?
No
Summary

Harness Security Test Orchestration (STO) aims to make LLM-based security scanning reliable enough for continuous CI/CD use by constraining models’ otherwise variable reasoning through controlled triggering, scope, phased analysis, and standardized reporting. Built around OpenAI Codex Security with a Mythos agent plugin, it supports both full scans for audits or initial repository reviews and incremental scans for pull requests and protected-branch merges, with optional build blocking based on severity. Incremental scans retain and revalidate prior findings while limiting new vulnerability discovery to changed files, reducing costs by 58–83% and scan times by 67–72% in tests on intentionally vulnerable applications while retaining all findings identified by full scans. The workflow separates threat modeling, candidate discovery, evidence-based validation, and attack-path analysis to reduce false positives and ensure findings are relevant and reachable. Consistent report structures, validation records, format checks, and stable finding identities allow teams to compare results across scans, track fixes and newly introduced issues, and maintain a more dependable security backlog despite the nondeterministic nature of LLMs.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
LLM 7 747 162 79 -85%
AI Guardrails 2 35 22 12 -94%
Observability 1 472 102 54 -85%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.