HarnessmarketEnter the desk
/HMX Claude Code 29.1%/Open index 519 slips/Meridian desk 6,400 agents live/Skills + MCP 553,855 indexed (Skillful, Aug 2026)/Agent Skills spec 1.2M+ open packages/Deloitte: orchestration worth +15–30% of autonomous-agent TAM by 2030/Gartner: 40% of agentic projects cancelled by 2027 without a supervisor/SWE-bench Pro: harness swap > many model upgrades/HM-SWE-Pro: Loop+Claude 41.2 pass@1 · chat 18.2 · same model/Lewis 2608.26218: F2PF 28→49 under a tighter harness, same model/ACES: Skill Lift 0.21 · 947 paired cases · scan vs live ρ=0.14/Tokenomics: code review 59.4% of ChatDev tokens/HMX Claude Code 29.1%/Open index 519 slips/Meridian desk 6,400 agents live/Skills + MCP 553,855 indexed (Skillful, Aug 2026)/Agent Skills spec 1.2M+ open packages/Deloitte: orchestration worth +15–30% of autonomous-agent TAM by 2030/Gartner: 40% of agentic projects cancelled by 2027 without a supervisor/SWE-bench Pro: harness swap > many model upgrades/HM-SWE-Pro: Loop+Claude 41.2 pass@1 · chat 18.2 · same model/Lewis 2608.26218: F2PF 28→49 under a tighter harness, same model/ACES: Skill Lift 0.21 · 947 paired cases · scan vs live ρ=0.14/Tokenomics: code review 59.4% of ChatDev tokens

Market · 2026-08-12 · 11 min

Licensing, git, and the coming IP layer

A Skill is a work. A harness is a work. A mix is a process. Someone will want to know who owns each, who may run each, and which SHA did.

Harnessmarket Intelligence

Git is not a feature we added because developers like git. Git is the only provenance model the industry already trusts. Every artifact on this market is a tree: SKILL.md, scripts, permission manifest, SBOM, signature, semver tag. `hm install lattice/plan-work-review@2.4.1` is `git fetch` plus an entitlement check. If that sounds like npm, it is because npm was the last time a capability market worked, and also the last time a capability market was a supply-chain incident at global scale. We are repeating both, faster.

Licensing splits four ways. OSS (MIT, Apache-2.0) is the CLI and the Skill body. Seat is the IDE-shaped harness and the process Skill. Usage is the hosted worker and the metered advance (KV-cache scheduler bills against observed savings). Enterprise is the supervisor, the attribution pack, the evidence pack — anything whose customer is an organisation rather than a developer. Dual-license is the Codex pattern and will be the default for labs that want an open shell and a closed runtime.

The IP question that has not been litigated properly: if three harnesses and two skills produced a merged PR, who owns the diff? Token share is the wrong answer. Accepted-work share plus the git trail is the beginning of an answer. License liability share is what the insurance market will eventually want. This desk already computes all three so that the first serious dispute is not also the first time anyone looked.

Publisher economics are deliberately boring. 12% take on paid artifacts, 88% to the studio, no listing fee, payouts weekly, certified-tier review is a paid scan through Northstar rather than a taste-making editor. Managed-tier is the lab's own SLA. Community-tier is unsigned and cannot load on a production fleet with `prodOnlySigned`. That last line is the whole security product.