Reference implementation
HarnessRouter Runtime Plugins
Runtime Plugins are HarnessRouter services connected at workspace scope and included explicitly per harness; they are not UHP package plugins.
The model
Section titled “The model”PR #266, released in HarnessRouter v0.24.0, adds a plugin service plane. A workspace connects a service once; each harness explicitly includes or excludes it.
The first shipped plugin is browser use. HarnessRouter exposes browser tools through its plugs/MCP layer while keeping vendor credentials and the browser address out of the agent.
Not the same as UHP Harness Plugins
Section titled “Not the same as UHP Harness Plugins”| Runtime Plugins | UHP Harness Plugins |
|---|---|
| HarnessRouter implementation feature | UHP protocol feature |
| Connected service at workspace scope | Agent Plugins package carried on a harness |
| Included per harness | Installed/bound through protocol package semantics |
| Browser service is first implementation | Package may contain MCP servers and skills |
The names overlap, but the lifecycle, ownership and transport are different.
Security boundary
Section titled “Security boundary”The browser service refuses private, loopback, link-local and metadata-address targets and applies domain allow/deny policy. Nothing is included by default.
These controls are HarnessRouter implementation behavior, not normative UHP requirements.