SIGN IN SIGN UP

feat(integrations): add shared harness contract module to core (#2746)

Stacked on #2743. Part 1 of the harness consolidation stack (see plan).

## What

Adds `@browserbasehq/stagehand-integrations/harness` — the shared
contract module for harness adapters:

- **Contract stays in evals** (reshaped after review): `AgentMount`,
`AgentRunToolSpec`, and the run-tool constants remain in
`packages/evals/core/contracts/tool.ts`; the harness module carries only
shared utilities and seam types. Integrations never imports from evals —
dependency direction is evals → integrations.
- **New seam types** for the upcoming adapter packages:
`StartedSurface`, `HarnessTask`, `HarnessLogger` (deliberately no
`getLogs`), `HarnessAdapterError`.
- **`sanitizeErrorMessage` dedupe**: the codexCodeBridge copy was a
2-rule subset of the facade stdio-server's 5 rules (drifted). Single
merged superset in `harness/redact.ts`; both callers rewired. Only
behavior change in the PR: bridge redaction widens to the superset.
- **`buildAllowlistedEnv` dedupe**: one copy replaces 4 identical ones
(vercel-ai, mastra, claude-code, codex examples). All four verified
identical before merging.

## Verification

- turbo build/typecheck/test:unit across the affected graph (26 tasks) +
full unit suite + lint/fmt ✅
- New `core/tests/harness.test.ts`: per-rule redaction assertions (both
source rule sets survive the merge), env allowlist behavior, run-tool
constant derivation
- Example tests unchanged except import paths (assertions identical)
- `codex exec review` second-opinion pass: no source findings

<!-- This is an auto-generated description by cubic. -->
---
## Summary by cubic
Centralizes harness utilities in
`@browserbasehq/stagehand-integrations/harness` to share env
allowlisting and error redaction across adapters. The codex bridge
switches from a 2-rule subset to the 5-rule superset redaction, so more
secrets are redacted; no other behavior changes.

- Keeps the agent mount contract in
`packages/evals/core/contracts/tool.ts`;
`@browserbasehq/stagehand-integrations/harness` exports
`sanitizeErrorMessage`, `buildAllowlistedEnv`, `HarnessLogger`, and
`HarnessAdapterError` only.
- Replaces four duplicate `buildAllowlistedEnv` copies in `vercel-ai`,
`mastra`, `claude-code`, and `codex`; tests/examples now import from
`@browserbasehq/stagehand-integrations/harness`.
- De-duplicates `sanitizeErrorMessage`; both the facade stdio server and
the codex bridge import the shared superset (core uses explicit `.js`
ESM specifiers).
- Adds `packages/integrations/core/tests/harness.test.ts` for redaction
and env allowlist; expands `packages/evals/.gitignore` to exclude run
artifacts.

<sup>Written for commit 948c4c30cf3abef6230afdf7e2f3dc95400c1bd8.
Summary will update on new commits.</sup>

<a
href="https://cubic.dev/pr/browserbase/stagehand/pull/2746?utm_source=github"
target="_blank" rel="noopener noreferrer"
data-no-image-dialog="true"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"><source
media="(prefers-color-scheme: light)"
srcset="https://www.cubic.dev/buttons/review-in-cubic-light.svg"><img
alt="Review in cubic"
src="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"></picture></a>

<!-- End of auto-generated description by cubic. -->
M
Miguel committed
26c4aa8b94aebb103ab0bcc86e6e7d3bb970a797
Parent: 97bb55c
Committed by GitHub <noreply@github.com> on 8/30/2026, 6:09:38 AM