← Reference · Nestor G Pestelos Jr · Print this page

Artificial Intelligence · Systems Architecture

Agent Harness

Reference entry · last updated 20260915

Previous version, captured 20260915

An agent harness is the software and runtime environment surrounding a foundation model that manages its execution. It supplies tools, context, state, feedback, and permission controls.[1]

User Goal Task Input Agent Harness Infrastructure Context & Memory Compaction · Files Foundation Model (Compute / CPU) Tool Execution Bash · Git · APIs Verification & Guardrails Loop Linters · Unit Tests · Gate Approvals Environment Code · Production

First principles: a computer architecture analogy

Beren Millidge compares scaffolded language models to a computer. The mapping is an analogy: language-model outputs lack the reliability of CPU instructions.[3]

Harness changes and measured performance

In a 20260217 report, LangChain's Vivek Trivedy described improving deepagents-cli from 52.8% to 66.5% on Terminal Bench 2.0 while keeping GPT-5.2-Codex fixed. The team changed the harness, including prompts, tools, and middleware, and adjusted reasoning budgets.[4]

This result shows an improvement for that agent and benchmark. It does not establish that harness changes generally outperform model upgrades, or isolate verification as the cause of the gain.

Twelve architectural components

These twelve items group harness responsibilities from the cited designs for illustration. A system may combine them or omit features it does not need.

  1. Orchestration loop: Calls the model, executes tools, and returns their results for the next step.[1]
  2. Tool interface: Defines available actions and their inputs. Anthropic recommends clear tools with little overlap.[2]
  3. Memory layer: Stores notes outside the context window and retrieves them when needed.[2]
  4. Context management: Summarizes older conversation and clears redundant tool results. Compaction can lose details that later matter.[2]
  5. Prompt assembly: Selects system instructions, tool descriptions, external data, and message history for each call.[2]
  6. Input/output handling: Passes requests to the model and routes tool calls to execution infrastructure.[1]
  7. State persistence: Uses progress files and Git history to help later sessions resume work.[5]
  8. Error handling: Provides recovery paths after failures, such as restoring a working Git state.[5]
  9. Guardrails: Uses hooks and sandbox restrictions to enforce action boundaries.[1]
  10. Verification loops: Runs tests and returns failures to the agent. In Anthropic's web-app experiments, browser testing exposed defects that code inspection missed.[5]
  11. Subagent management: Delegates focused tasks to separate contexts and collects their results.[2]
  12. Execution flow: Controls when work continues or stops, including checks before completion.[4]

Skills and runtime responsibilities

Agent Skills package task instructions in SKILL.md files and can include scripts and reference material. Compatible agents load them when relevant.[6]

Runtime code enforces permissions, invokes tools, and runs checks at defined lifecycle points. A written instruction to avoid an action is not an enforcement boundary.[1]

Skills make procedures easier to reuse, but format compatibility does not ensure identical behavior. Millidge notes that model-specific prompts and failsafes limit portability; LangChain likewise recommends tuning harnesses for the model and task.[3, 4] Portability therefore needs testing in the destination environment.

See also

References

  1. ↑ Osmani, Addy. “Agent Harness Engineering.” 20260419.
  2. ↑ Anthropic Applied AI team. “Effective context engineering for AI agents.” 20250929.
  3. ↑ Millidge, Beren. “Scaffolded LLMs as natural language computers.” 20230411.
  4. ↑ Trivedy, Vivek. “Improving Deep Agents with harness engineering.” LangChain, 20260217.
  5. ↑ Young, Justin. “Effective harnesses for long-running agents.” Anthropic, 20251126.
  6. ↑ Agent Skills. “Agent Skills Overview.” Accessed 20260915.