Security Review
ChatbotXIO/ChatbotX
Use before committing changes to auth, workspace scoping, channel webhooks, AI tools/MCP, permission settings, or anything handling untrusted channel content in ChatbotX.
Security hardening guidance for AI agent frameworks that process untrusted content, invoke tools, write workspace files, manage runtime identifiers, or handle credentials.
$ npx skills add affaan-m/ECC --skill agent-security-hardening -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install affaan-m/ECC agent-security-hardening --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/affaan-m/ECC.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/agent-security-hardening .claude/skills/agent-security-hardening && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "agent-security-hardening" agent skill from https://github.com/affaan-m/ECC/tree/main/skills/agent-security-hardening into .claude/skills/agent-security-hardening/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "agent-security-hardening", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/affaan-m/ECC/tree/main/skills/agent-security-hardeningType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add affaan-m/ECC --skill agent-security-hardening -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install affaan-m/ECC agent-security-hardening --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/affaan-m/ECC.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/agent-security-hardening .agents/skills/agent-security-hardening && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "agent-security-hardening" agent skill from https://github.com/affaan-m/ECC/tree/main/skills/agent-security-hardening into .agents/skills/agent-security-hardening/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "agent-security-hardening", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add affaan-m/ECC --skill agent-security-hardening -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install affaan-m/ECC agent-security-hardening --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/affaan-m/ECC.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/agent-security-hardening .cursor/skills/agent-security-hardening && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "agent-security-hardening" agent skill from https://github.com/affaan-m/ECC/tree/main/skills/agent-security-hardening into .cursor/skills/agent-security-hardening/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "agent-security-hardening", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/affaan-m/ECC.git --path skills/agent-security-hardening--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add affaan-m/ECC --skill agent-security-hardening -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install affaan-m/ECC agent-security-hardening --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/affaan-m/ECC.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/agent-security-hardening .gemini/skills/agent-security-hardening && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "agent-security-hardening" agent skill from https://github.com/affaan-m/ECC/tree/main/skills/agent-security-hardening into .gemini/skills/agent-security-hardening/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "agent-security-hardening", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install affaan-m/ECC agent-security-hardeningInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add affaan-m/ECC --skill agent-security-hardening -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/affaan-m/ECC.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/agent-security-hardening .github/skills/agent-security-hardening && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "agent-security-hardening" agent skill from https://github.com/affaan-m/ECC/tree/main/skills/agent-security-hardening into .github/skills/agent-security-hardening/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "agent-security-hardening", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add affaan-m/ECC --skill agent-security-hardening -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install affaan-m/ECC agent-security-hardening --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/affaan-m/ECC.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/agent-security-hardening .opencode/skills/agent-security-hardening && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "agent-security-hardening" agent skill from https://github.com/affaan-m/ECC/tree/main/skills/agent-security-hardening into .opencode/skills/agent-security-hardening/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "agent-security-hardening", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
agent-security-hardeningSecurity hardening guidance for AI agent frameworks that process untrusted content, invoke tools, write workspace files, manage runtime identifiers, or handle credentials.
Agent Security Hardening is an agent skill from affaan-m/ECC. Security hardening guidance for AI agent frameworks that process untrusted content, invoke tools, write workspace files, manage runtime identifiers, or handle credentials. Use when building or reviewing an agent runtime, autonomous worker, tool gateway, memory service, or multi-tenant agent deployment. Do not use for general web application security or offensive testing.
Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Prompt injection and agent security, Multi-tenancy and Building AI agents. The repository describes itself as: The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond. The licence is MIT.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 4eb71d9. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are python).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Agent Security Hardening loads about 2.7k tokens when it runs. Until then it costs about 100 tokens; SKILL.md has 1,151 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from affaan-m/ECC at commit 4eb71d9, republished under its MIT licence (© affaan-m). 1,151 words, ~2,668 tokens.
.claude/skills/agent-security-hardening/SKILL.md (or your agent's skills folder).Harden the boundaries where an agent turns untrusted data into filesystem, network, memory, or tool actions. Produce concrete controls and tests for the framework being reviewed; a checklist without enforcement evidence is incomplete.
List every boundary as source -> parser -> validator -> side effect. Include direct user input, model output, retrieved documents, memory, environment variables, tool results, and messages from other agents.
For each side effect, record:
This step is complete when every write, command, network mutation, and credential use has one named authorization boundary.
Use an allowlist for identifiers that become filenames, keys, selectors, or command arguments. Agent IDs have the issue-defined hard maximum of 64 characters; deployment configuration may choose a stricter positive limit but cannot raise that boundary:
import re
SAFE_AGENT_ID_CHARS = re.compile(r"^[A-Za-z0-9_][A-Za-z0-9_-]*$")
HARD_MAX_AGENT_ID_LENGTH = 64
def require_agent_id(value: object, *, max_length: int) -> str:
if (
isinstance(max_length, bool)
or not isinstance(max_length, int)
or not 1 <= max_length <= HARD_MAX_AGENT_ID_LENGTH
):
raise RuntimeError("configured agent ID limit must be between 1 and 64")
if (
not isinstance(value, str)
or len(value) > max_length
or not SAFE_AGENT_ID_CHARS.fullmatch(value)
):
raise ValueError("invalid agent identifier")
return valueWhen an identifier becomes a CLI argument, pass it through an argv API and place it after the command's end-of-options marker where supported. Character validation is not a substitute for argument separation.
Reject missing and whitespace-only environment values before constructing a client:
def require_env(name: str, environ: dict[str, str]) -> str:
value = environ.get(name)
if value is None or not value.strip():
raise RuntimeError(f"{name} is required")
return valueParse URLs, allow only schemes required by the deployment, require a host, reject embedded credentials, and block private-network destinations when the URL is attacker-controlled. For every outbound connection and redirect hop, pin the connection to a validated public address or verify the connected peer address at connection time so DNS rebinding cannot cross the boundary. A credential-bearing request must use HTTPS with certificate verification before credentials are attached. Disable automatic cross-origin credential forwarding; when the scheme or origin changes, strip the credentials and reauthorize the new destination or reject the redirect. Re-run destination, connected-address, and transport validation on every hop.
This step is complete when tests reject empty, oversized, malformed, traversal-shaped, credential-bearing, and unauthorized-destination values before any side effect, and prove that DNS rebinding and cross-origin redirects cannot carry credentials to an unapproved peer.
Reject absolute user-controlled paths and traversal components before joining. Reject Windows-unsafe components on every platform so behavior stays portable: reserved device names (CON, NUL, COM1, LPT1, including with an extension such as nul.txt), names ending in a dot or space (Win32 strips them), and : (drive-relative or NTFS alternate data stream syntax such as report.txt:ads). Resolve both the workspace and candidate path, then prove containment:
import re
from pathlib import Path
WINDOWS_RESERVED_NAME = re.compile(
r"(CON|PRN|AUX|NUL|COM[1-9¹²³]|LPT[1-9¹²³])(\..*)?",
re.IGNORECASE,
)
def workspace_path(workspace: Path, requested: str) -> Path:
# Treat both platform separators consistently before checking components.
relative = Path(requested.replace("\\", "/"))
if relative.is_absolute() or ".." in relative.parts:
raise ValueError("path must be workspace-relative")
for part in relative.parts:
if ":" in part or part.endswith((".", " ")) or WINDOWS_RESERVED_NAME.fullmatch(part):
raise ValueError("path component is not portable")
root = workspace.resolve(strict=True)
candidate = (root / relative).resolve(strict=False)
if not candidate.is_relative_to(root):
raise ValueError("path escapes workspace")
return candidateContainment checks do not eliminate symlink races. For sensitive writes, open relative to a trusted directory handle where the platform supports it, reject symlink targets, create files exclusively, and verify ownership and permissions after opening.
This step is complete when tests cover sibling-prefix paths, nested .., absolute paths, symlink escapes, reserved device names, trailing dots or spaces, alternate data stream syntax, and a valid nested workspace path.
0o600; create private directories with 0o700.finally, while preserving a redacted error record when cleanup fails.This step is complete when file-mode checks, forced-error cleanup tests, and log-capture tests show that secret values never persist outside the approved boundary.
Read tool output with a byte limit rather than collecting an unbounded stream. Preserve structured fields, remove disallowed control characters, and append an explicit truncation marker with the original byte count. Keep a content hash when later forensic comparison matters.
Do not silently turn malformed output into an empty success value. Return a typed failure that names the producing tool, boundary, and validation reason without echoing sensitive content.
This step is complete when oversized output, invalid encoding, terminal-control sequences, malformed structured data, and a normal response all have deterministic tests.
Before calling the framework hardened, verify all of these behaviors through its real entry point:
Report the command used, exit status, rejected input, and observed absence of the side effect. Mock-only tests do not prove operating-system permissions, symlink handling, subprocess isolation, or network egress controls.
Prompt instructions are advisory. Move the same invariant into deterministic code immediately before the side effect and test a model response that violates it.
String prefix checks confuse sibling paths such as /work/app and /work/application. Resolve paths and use component-aware containment, then test symlinks separately.
Redact before values enter the logger, tracer, exception, or model context. Add a capture test using a sentinel secret and assert the sentinel is absent from every emitted channel.
security-review for ordinary application authentication, authorization, SQL injection, XSS, CSRF, and API security.security-scan for repository-wide automated vulnerability scanning.agent-harness-constructionsecurity-reviewsecurity-scan© affaan-m, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/agent-security-hardening of affaan-m/ECC.
Open the folder on GitHubat commit 4eb71d9
Agent Security Hardening next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Agent Security Hardening this skillaffaan-m/ECC | 276k | — | ~2.7k | Automated safety check: Pass | MIT | |
| Security ReviewChatbotXIO/ChatbotX | 885 | — | ~1.8k | Automated safety check: Notes | Custom licence | |
| Security Passcyanheads/pubmed-mcp-server | 158 | — | ~6.4k | Automated safety check: Pass | Apache-2.0 | |
| Kesekit Checkcdppcorp/KESE-KIT | 360 | — | ~1.3k | Automated safety check: Pass | MIT | |
| Agentic GitHub Actions Auditortrailofbits/skills | 7.5k | 6 repos | ~5.4k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| AI SAFE2 Secure Build CopilotCyberStrategyInstitute/ai-safe2-framework | 147 | — | ~2.7k | Automated safety check: Pass | Custom licence |
ChatbotXIO/ChatbotX
Use before committing changes to auth, workspace scoping, channel webhooks, AI tools/MCP, permission settings, or anything handling untrusted channel content in ChatbotX.
cyanheads/pubmed-mcp-server
Review an MCP server for common security gaps: LLM-facing surfaces as injection vector (tools, resources, prompts, descriptions), scope blast radius, destructive ops without consent, upstream auth…
cdppcorp/KESE-KIT
Run a pre-deployment security compliance checklist based on KISA guidelines.
trailofbits/skills
Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.
CyberStrategyInstitute/ai-safe2-framework
Applies the AI SAFE2 v3.1 governance framework to designing, building, auditing and testing AI agents, RAG pipelines, MCP and tool integrations and AI infrastructure.
langfuse/langfuse
Review Langfuse changes for SSRF, tenant isolation, secret handling, unsafe redirects or uploads, RBAC drift, and client telemetry privacy.
affaan-m/ECC
Audits your installed Claude skills and commands for quality, with a quick mode for recently changed skills and a full mode that evaluates all of them through subagents.
affaan-m/ECC
Ingests, indexes, searches, edits and monitors video, audio and live streams through the VideoDB Python SDK, returning stream links, clips and timestamps.
affaan-m/ECC
Route broad documentation-governance requests to existing ECC skills and run an opt-in, read-only audit of mapped documentation roles, links, ADR indexes, and evidence references.
affaan-m/ECC
Scans installed skills for principles that recur across them and proposes rule-file changes: append, revise, add a section, create a file or leave as covered.
affaan-m/ECC
Builds DRAFT counterparty agreements from one markdown template and a small JSON spec per party, with clauses picked by the party's role.
affaan-m/ECC
Set an ECC-specific frontend design direction for production UI work.
Security hardening guidance for AI agent frameworks that process untrusted content, invoke tools, write workspace files, manage runtime identifiers, or handle credentials. Agent Security Hardening is an agent skill from affaan-m/ECC. Security hardening guidance for AI agent frameworks that process untrusted content, invoke tools, write workspace files, manage runtime identifiers, or handle credentials.
Agent Security Hardening fits situations like: reviewing an agent runtime; autonomous worker; multi-tenant agent deployment; general web application security.
Run `npx skills add affaan-m/ECC --skill agent-security-hardening -a claude-code`. Or copy the skill folder (skills/agent-security-hardening in affaan-m/ECC) into .claude/skills/agent-security-hardening in your project. Claude Code loads it when a task matches its description.
Run `npx skills add affaan-m/ECC --skill agent-security-hardening -a codex`. Or copy the skill folder (skills/agent-security-hardening in affaan-m/ECC) into .agents/skills/agent-security-hardening in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add affaan-m/ECC --skill agent-security-hardening -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/agent-security-hardening, .gemini/skills/agent-security-hardening, .github/skills/agent-security-hardening and .opencode/skills/agent-security-hardening in your project.
SKILL.md names no scripts, command-line tools or credentials: Agent Security Hardening is instructions for the agent only. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Agent Security Hardening is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Agent Security Hardening: Security Review (ChatbotXIO/ChatbotX, 885 stars), Security Pass (cyanheads/pubmed-mcp-server, 158 stars), Kesekit Check (cdppcorp/KESE-KIT, 360 stars) and Agentic GitHub Actions Auditor (trailofbits/skills, 7.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
affaan-m (a GitHub user) maintains it in affaan-m/ECC, which has 276,111 GitHub stars. The repository holds 683 skills in this directory. The repository was last updated on October 10, 2026.
Source: affaan-m/ECC on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.