 AI 生成。](https://yishiashia.github.io/posts/harness-engineering-governance/harness_hero_hu1e0a75492d2642b7ace5326fbed083f2_237290_360x0_resize_q75_h2_box_2.webp)
[AI 軟體工程] Harness Engineering 介紹:用驗證與治理讓 AI Agent 的產出更可靠
這篇文章是《Harness Engineering:讓自主 AI 軟體工程可被信任的治理方法論》系列的總覽,也可以獨立閱讀。本篇先從問題與整體框架出發,整理出「合約、證據、見證、授權」四個治理支柱。 前言 用過 Claude Code、Codex 或 GitHub Copilot 這類 coding agent 的人,大概都有過一種矛盾的感受:它產出程式碼的速度快得驚人,快到你根本來不及一行一行看完。 一開始會覺得:這太讚了吧,工作速度與效率都明顯提高了。 但問題是,AI 產 code 的速度實在太快了,人類 review 的速度根本跟不上。為了維持產出的速度,最後常常乾脆選擇相信 AI,直接 approve 或 merge,但內心總是忍不住懷疑:這樣真的對嗎? 這段程式碼真的是照當初講好的需求做的嗎? 出事的時候,責任算誰的? 它有沒有悄悄違反我們的架構決策? 到底什麼時候才能安全地把它合併、上線? 先前介紹 WebMCP 時有提到:涉及交易或破壞性的重要操作,一定要設計「Human-in-the-loop」的最後確認機制。那句話其實只是冰山一角。當 AI 從「幫你查資料的聊天機器人」變成「幫你動手改 code 的 agent」,我們需要的就不再只是「一個確認按鈕」,而是一整套讓機器產出可被信任的工程方法。 這套「讓機器產出可被信任」的工程方法,最近開始被稱作 harness engineering。這個詞會廣為人知,很大一部分要歸功於 OpenAI 的一篇文章 《Harness engineering: leveraging Codex in an agent-first world》:他們分享了一種「工程師幾乎不親手寫 code,而是去打造讓 agent 不出錯的結構、文件與自動檢查」的 agent-first 開發實踐。而這個系列想談的,不是怎麼操作某個工具,而是它背後的治理方法論。 什麼是 harness engineering? 先講「harness」這個字。它原本是「馬具、輓具」的意思 —— 套在馬身上、讓馬的力氣能被駕馭、用在對的方向上的那組裝備。 放到 AI 的世界,harness 指的是「讓一個語言模型變成可靠 agent 的那層骨架」:工具(tools)、流程(workflow)、驗收(verification)、授權(authorization)。模型負責「產出」,harness 則決定「這份能力怎麼被安全地使用」。...
 AI 生成。](https://yishiashia.github.io/posts/webmcp-introduction/webmcp_hero_hubbd9414c4a21b157ae325276f65c4d0f_427880_360x0_resize_q75_h2_box_2.webp)
 AI 生成。](https://yishiashia.github.io/posts/chrome-devtool-mock-api/mock_api_hero_hu8da9743bb73b86f381d5a3c8a5440abd_53294_360x0_resize_q75_h2_box_2.webp)
 on [Unsplash](https://unsplash.com/)](https://yishiashia.github.io/posts/webcomponent-introduction-3/photo-1507787090700-dea2089be848_hu8eee3e06657eba56c336a312cd4fa41f_493336_360x0_resize_q75_h2_box_2.webp)
 on [Unsplash](https://unsplash.com/)](https://yishiashia.github.io/posts/webcomponent-introduction-2/photo-1530811761207-8d9d22f0a141_hufc2363791d5b26ee71905b9d1bcb064f_238958_360x0_resize_q75_h2_box_2.webp)
 on [Unsplash](https://unsplash.com/)](https://yishiashia.github.io/posts/my-webcomponents/maik-jonietz-_yMciiStJyY-unsplash_hu03d509ac765b9a6982ad06ca16e462ac_3555244_360x0_resize_q75_h2_box_2.webp)
 on [Unsplash](https://unsplash.com/)](https://yishiashia.github.io/posts/webcomponent-introduction-1/photo-1508921340878-ba53e1f016ec_hubf679cf552626ca82f0a99f95dda27de_323668_360x0_resize_q75_h2_box_2.webp)
 on [Unsplash](https://unsplash.com/)](https://yishiashia.github.io/posts/dark-mode-and-css-color-scheme/photo-1552862750-746b8f6f7f25_hu10fc2a13aff43a8f0553057e14b4b15c_178674_360x0_resize_q75_h2_box_2.webp)
 on [Unsplash](https://unsplash.com/)](https://yishiashia.github.io/posts/passkey-and-webauthn-passwordless-authentication/0_1zYBySFcoREDdevX_hucbe6c4c2db4a928d971b2e99c94c81b4_16006_360x0_resize_q75_h2_box_2.webp)
 on [Unsplash](https://unsplash.com/)](https://yishiashia.github.io/posts/introduction-to-basic-cryptography/0_Li0quUCV8yxJl8dT_huea44261cb67b614aa7200a94893d0e2c_55402_360x0_resize_q75_h2_box_2.webp)