Agent skill

Agent Security Hardening

by affaan-m in affaan-m/ECC

Security hardening guidance for AI agent frameworks that process untrusted content, invoke tools, write workspace files, manage runtime identifiers, or handle credentials.

MITAuto-check passedSecurity

Install Agent Security Hardening

skills CLI
$ npx skills add affaan-m/ECC --skill agent-security-hardening -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install affaan-m/ECC agent-security-hardening --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/affaan-m/ECC.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/agent-security-hardening .claude/skills/agent-security-hardening && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
agent-security-hardening
GitHub stars
276k
Token cost
~2.7k tokens
SKILL.md length
1,151 words
Files
1
Skills in repo
683
Repo updated
First seen
Licence
MIT

At a glance

Security hardening guidance for AI agent frameworks that process untrusted content, invoke tools, write workspace files, manage runtime identifiers, or handle credentials.

  • Works in 5 steps: Map Trust Boundaries → Validate Identifiers, Environment… → Contain Filesystem Access → …
  • Reviewing an agent runtime
  • SKILL.md covers Important, When to Activate, Hardening Workflow and Verification Gate, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Agent Security Hardening is an agent skill from affaan-m/ECC. Security hardening guidance for AI agent frameworks that process untrusted content, invoke tools, write workspace files, manage runtime identifiers, or handle credentials. Use when building or reviewing an agent runtime, autonomous worker, tool gateway, memory service, or multi-tenant agent deployment. Do not use for general web application security or offensive testing.

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Prompt injection and agent security, Multi-tenancy and Building AI agents. The repository describes itself as: The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond. The licence is MIT.

When your agent uses it

  • Reviewing an agent runtime
  • Autonomous worker
  • Multi-tenant agent deployment
  • General web application security

Example prompts

  • “/agent-security-hardening”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Map Trust Boundaries
  2. Validate Identifiers, Environment Values, and URLs
  3. Contain Filesystem Access
  4. Protect Temporary Data and Credentials
  5. Bound and Sanitize Tool Output

What it can do on your machine

Read from SKILL.md and the folder at commit 4eb71d9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are python).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Agent Security Hardening loads about 2.7k tokens when it runs. Until then it costs about 100 tokens; SKILL.md has 1,151 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~100
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from affaan-m/ECC at commit 4eb71d9, republished under its MIT licence (© affaan-m). 1,151 words, ~2,668 tokens.

Download SKILL.mdSave it as .claude/skills/agent-security-hardening/SKILL.md (or your agent's skills folder).
name
agent-security-hardening
description
Security hardening guidance for AI agent frameworks that process untrusted content, invoke tools, write workspace files, manage runtime identifiers, or handle credentials. Use when building or reviewing an agent runtime, autonomous worker, tool gateway, memory service, or multi-tenant agent deployment. Do not use for general web application security or offensive testing.
metadata.origin
ECC

Agent Security Hardening

Harden the boundaries where an agent turns untrusted data into filesystem, network, memory, or tool actions. Produce concrete controls and tests for the framework being reviewed; a checklist without enforcement evidence is incomplete.

Important

  • Treat model output, retrieved content, tool output, memory, and cross-agent messages as untrusted input.
  • Default external integrations to read-only and grant each write capability separately.
  • Validate at the action boundary even when an upstream prompt or schema already validated the value.
  • Fail closed before a side effect when identity, destination, ownership, or containment cannot be proven.
  • Before a delete, publish, credential rotation, or other irreversible action, the real tool entry point must authorize the authenticated principal for that exact operation and resource scope, then require explicit confirmation or a valid scoped pre-approval. Missing or invalid evidence blocks the action.
  • Use hard bounds defined by the governing requirement and stricter values verified from deployment configuration. When neither defines a value, mark it as a required decision and test that the implementation rejects an unbounded configuration; do not invent a plausible value.

When to Activate

  • Building an autonomous agent, tool gateway, memory service, or agent-to-agent protocol
  • Reviewing code that maps model output into commands, paths, URLs, credentials, or API mutations
  • Isolating tenants, projects, sessions, or workspaces in a long-running agent process
  • Hardening temporary files, logs, tool responses, or external-content ingestion

Hardening Workflow

1. Map Trust Boundaries

List every boundary as source -> parser -> validator -> side effect. Include direct user input, model output, retrieved documents, memory, environment variables, tool results, and messages from other agents.

For each side effect, record:

  • the identity and scope authorizing it;
  • the exact validator that runs immediately before it;
  • the maximum input and output size;
  • the audit evidence produced;
  • the recovery path if the operation is interrupted.

This step is complete when every write, command, network mutation, and credential use has one named authorization boundary.

2. Validate Identifiers, Environment Values, and URLs

Use an allowlist for identifiers that become filenames, keys, selectors, or command arguments. Agent IDs have the issue-defined hard maximum of 64 characters; deployment configuration may choose a stricter positive limit but cannot raise that boundary:

python
import re

SAFE_AGENT_ID_CHARS = re.compile(r"^[A-Za-z0-9_][A-Za-z0-9_-]*$")
HARD_MAX_AGENT_ID_LENGTH = 64

def require_agent_id(value: object, *, max_length: int) -> str:
    if (
        isinstance(max_length, bool)
        or not isinstance(max_length, int)
        or not 1 <= max_length <= HARD_MAX_AGENT_ID_LENGTH
    ):
        raise RuntimeError("configured agent ID limit must be between 1 and 64")
    if (
        not isinstance(value, str)
        or len(value) > max_length
        or not SAFE_AGENT_ID_CHARS.fullmatch(value)
    ):
        raise ValueError("invalid agent identifier")
    return value

When an identifier becomes a CLI argument, pass it through an argv API and place it after the command's end-of-options marker where supported. Character validation is not a substitute for argument separation.

Reject missing and whitespace-only environment values before constructing a client:

python
def require_env(name: str, environ: dict[str, str]) -> str:
    value = environ.get(name)
    if value is None or not value.strip():
        raise RuntimeError(f"{name} is required")
    return value

Parse URLs, allow only schemes required by the deployment, require a host, reject embedded credentials, and block private-network destinations when the URL is attacker-controlled. For every outbound connection and redirect hop, pin the connection to a validated public address or verify the connected peer address at connection time so DNS rebinding cannot cross the boundary. A credential-bearing request must use HTTPS with certificate verification before credentials are attached. Disable automatic cross-origin credential forwarding; when the scheme or origin changes, strip the credentials and reauthorize the new destination or reject the redirect. Re-run destination, connected-address, and transport validation on every hop.

This step is complete when tests reject empty, oversized, malformed, traversal-shaped, credential-bearing, and unauthorized-destination values before any side effect, and prove that DNS rebinding and cross-origin redirects cannot carry credentials to an unapproved peer.

3. Contain Filesystem Access

Reject absolute user-controlled paths and traversal components before joining. Reject Windows-unsafe components on every platform so behavior stays portable: reserved device names (CON, NUL, COM1, LPT1, including with an extension such as nul.txt), names ending in a dot or space (Win32 strips them), and : (drive-relative or NTFS alternate data stream syntax such as report.txt:ads). Resolve both the workspace and candidate path, then prove containment:

python
import re
from pathlib import Path

WINDOWS_RESERVED_NAME = re.compile(
    r"(CON|PRN|AUX|NUL|COM[1-9¹²³]|LPT[1-9¹²³])(\..*)?",
    re.IGNORECASE,
)

def workspace_path(workspace: Path, requested: str) -> Path:
    # Treat both platform separators consistently before checking components.
    relative = Path(requested.replace("\\", "/"))
    if relative.is_absolute() or ".." in relative.parts:
        raise ValueError("path must be workspace-relative")
    for part in relative.parts:
        if ":" in part or part.endswith((".", " ")) or WINDOWS_RESERVED_NAME.fullmatch(part):
            raise ValueError("path component is not portable")

    root = workspace.resolve(strict=True)
    candidate = (root / relative).resolve(strict=False)
    if not candidate.is_relative_to(root):
        raise ValueError("path escapes workspace")
    return candidate

Containment checks do not eliminate symlink races. For sensitive writes, open relative to a trusted directory handle where the platform supports it, reject symlink targets, create files exclusively, and verify ownership and permissions after opening.

This step is complete when tests cover sibling-prefix paths, nested .., absolute paths, symlink escapes, reserved device names, trailing dots or spaces, alternate data stream syntax, and a valid nested workspace path.

Show full SKILL.md (485 more words)Show less
4. Protect Temporary Data and Credentials
  • Create sensitive files with owner-only permissions such as 0o600; create private directories with 0o700.
  • Prefer a user-private runtime directory over a shared temporary directory for credentials or tenant data.
  • Create unpredictable names atomically; do not check-then-create.
  • Remove temporary data in finally, while preserving a redacted error record when cleanup fails.
  • Keep secrets out of command arguments, model context, logs, traces, exception text, and tool responses.
  • Pass secrets through the platform's secret store or scoped environment injection and rotate exposed credentials.
  • Treat zeroization as best effort: mutable byte buffers can be overwritten, but immutable language strings cannot be reliably erased.

This step is complete when file-mode checks, forced-error cleanup tests, and log-capture tests show that secret values never persist outside the approved boundary.

5. Bound and Sanitize Tool Output

Read tool output with a byte limit rather than collecting an unbounded stream. Preserve structured fields, remove disallowed control characters, and append an explicit truncation marker with the original byte count. Keep a content hash when later forensic comparison matters.

Do not silently turn malformed output into an empty success value. Return a typed failure that names the producing tool, boundary, and validation reason without echoing sensitive content.

This step is complete when oversized output, invalid encoding, terminal-control sequences, malformed structured data, and a normal response all have deterministic tests.

Verification Gate

Before calling the framework hardened, verify all of these behaviors through its real entry point:

  1. Untrusted instructions remain data and cannot trigger a tool or write.
  2. An irreversible action without operation-and-resource authorization plus confirmation or scoped pre-approval leaves no side effect.
  3. Cross-tenant and cross-workspace identifiers are rejected at the action boundary.
  4. Traversal and symlink escape attempts leave the filesystem unchanged.
  5. Forced failures leave no credential-bearing temp files or logs.
  6. Oversized or malformed tool output returns an explicit bounded error.

Report the command used, exit status, rejected input, and observed absence of the side effect. Mock-only tests do not prove operating-system permissions, symlink handling, subprocess isolation, or network egress controls.

Common Issues

Validation exists only in the prompt

Prompt instructions are advisory. Move the same invariant into deterministic code immediately before the side effect and test a model response that violates it.

A normalized path still escapes

String prefix checks confuse sibling paths such as /work/app and /work/application. Resolve paths and use component-aware containment, then test symlinks separately.

Redaction happens after logging

Redact before values enter the logger, tracer, exception, or model context. Add a capture test using a sentinel secret and assert the sentinel is absent from every emitted channel.

When NOT to Use

  • Use security-review for ordinary application authentication, authorization, SQL injection, XSS, CSRF, and API security.
  • Use security-scan for repository-wide automated vulnerability scanning.
  • Use infrastructure-specific guidance for host, container, firewall, or cloud hardening.
  • Do not use this skill for penetration testing, exploit development, or unauthorized access.
  • agent-harness-construction
  • security-review
  • security-scan

© affaan-m, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/agent-security-hardening of affaan-m/ECC.

Open the folder on GitHubat commit 4eb71d9

Compare with similar skills

Agent Security Hardening next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Agent Security Hardening compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Agent Security Hardening this skillaffaan-m/ECC276k—~2.7kAutomated safety check: PassMIT
Security ReviewChatbotXIO/ChatbotX885—~1.8kAutomated safety check: NotesCustom licence
Security Passcyanheads/pubmed-mcp-server158—~6.4kAutomated safety check: PassApache-2.0
Kesekit Checkcdppcorp/KESE-KIT360—~1.3kAutomated safety check: PassMIT
Agentic GitHub Actions Auditortrailofbits/skills7.5k6 repos~5.4kAutomated safety check: NotesCC-BY-SA-4.0
AI SAFE2 Secure Build CopilotCyberStrategyInstitute/ai-safe2-framework147—~2.7kAutomated safety check: PassCustom licence

Similar skills

  • Security Review

    ChatbotXIO/ChatbotX

    Use before committing changes to auth, workspace scoping, channel webhooks, AI tools/MCP, permission settings, or anything handling untrusted channel content in ChatbotX.

    885 GitHub stars~1.8k tokensUpdated 2 days ago
    SecurityAuto-check: notes
  • Security Pass

    cyanheads/pubmed-mcp-server

    Review an MCP server for common security gaps: LLM-facing surfaces as injection vector (tools, resources, prompts, descriptions), scope blast radius, destructive ops without consent, upstream auth…

    158 GitHub stars~6.4k tokensUpdated yesterday
    SecurityAuto-check passed
  • Kesekit Check

    cdppcorp/KESE-KIT

    Run a pre-deployment security compliance checklist based on KISA guidelines.

    360 GitHub stars~1.3k tokensUpdated 6 mo ago
    SecurityAuto-check passed
  • Official

    Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.

    7.5k GitHub starsUsed in 6 repos~5.4k tokens
    SecurityAuto-check: notes
  • AI SAFE2 Secure Build Copilot

    CyberStrategyInstitute/ai-safe2-framework

    Applies the AI SAFE2 v3.1 governance framework to designing, building, auditing and testing AI agents, RAG pipelines, MCP and tool integrations and AI infrastructure.

    147 GitHub stars~2.7k tokensUpdated yesterday
    SecurityAuto-check passed
  • Security Review

    langfuse/langfuse

    Review Langfuse changes for SSRF, tenant isolation, secret handling, unsafe redirects or uploads, RBAC drift, and client telemetry privacy.

    36k GitHub stars~1.4k tokensUpdated today
    SecurityAuto-check passed

More from affaan-m/ECC

All 682 skills in this repo
  • Skill Stocktake

    affaan-m/ECC

    Audits your installed Claude skills and commands for quality, with a quick mode for recently changed skills and a full mode that evaluates all of them through subagents.

    277k GitHub starsUsed in 5 repos~3.1k tokens
    Auto-check passed
  • Ingests, indexes, searches, edits and monitors video, audio and live streams through the VideoDB Python SDK, returning stream links, clips and timestamps.

    277k GitHub starsUsed in 3 repos~3.5k tokens
    Auto-check: notes
  • Docs Governance

    affaan-m/ECC

    Route broad documentation-governance requests to existing ECC skills and run an opt-in, read-only audit of mapped documentation roles, links, ADR indexes, and evidence references.

    277k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Rules Distillation

    affaan-m/ECC

    Scans installed skills for principles that recur across them and proposes rule-file changes: append, revise, add a section, create a file or leave as covered.

    277k GitHub starsUsed in 2 repos~2.3k tokens
    Auto-check passed
  • Builds DRAFT counterparty agreements from one markdown template and a small JSON spec per party, with clauses picked by the party's role.

    277k GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Set an ECC-specific frontend design direction for production UI work.

    277k GitHub starsUsed in 1 repo~2.2k tokens
    Auto-check passed

Questions about Agent Security Hardening

What does Agent Security Hardening do?

Security hardening guidance for AI agent frameworks that process untrusted content, invoke tools, write workspace files, manage runtime identifiers, or handle credentials. Agent Security Hardening is an agent skill from affaan-m/ECC. Security hardening guidance for AI agent frameworks that process untrusted content, invoke tools, write workspace files, manage runtime identifiers, or handle credentials.

When should I use Agent Security Hardening?

Agent Security Hardening fits situations like: reviewing an agent runtime; autonomous worker; multi-tenant agent deployment; general web application security.

How do I install Agent Security Hardening in Claude Code?

Run `npx skills add affaan-m/ECC --skill agent-security-hardening -a claude-code`. Or copy the skill folder (skills/agent-security-hardening in affaan-m/ECC) into .claude/skills/agent-security-hardening in your project. Claude Code loads it when a task matches its description.

How do I install Agent Security Hardening in Codex?

Run `npx skills add affaan-m/ECC --skill agent-security-hardening -a codex`. Or copy the skill folder (skills/agent-security-hardening in affaan-m/ECC) into .agents/skills/agent-security-hardening in your project. Codex loads it when a task matches its description.

Can I use Agent Security Hardening in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add affaan-m/ECC --skill agent-security-hardening -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/agent-security-hardening, .gemini/skills/agent-security-hardening, .github/skills/agent-security-hardening and .opencode/skills/agent-security-hardening in your project.

What does Agent Security Hardening need to run?

SKILL.md names no scripts, command-line tools or credentials: Agent Security Hardening is instructions for the agent only. Our summary lists: Python 3.

Does Agent Security Hardening access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Agent Security Hardening safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Agent Security Hardening use?

Agent Security Hardening is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Agent Security Hardening use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Agent Security Hardening?

Skills that share tags, products or a category with Agent Security Hardening: Security Review (ChatbotXIO/ChatbotX, 885 stars), Security Pass (cyanheads/pubmed-mcp-server, 158 stars), Kesekit Check (cdppcorp/KESE-KIT, 360 stars) and Agentic GitHub Actions Auditor (trailofbits/skills, 7.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Agent Security Hardening?

affaan-m (a GitHub user) maintains it in affaan-m/ECC, which has 276,111 GitHub stars. The repository holds 683 skills in this directory. The repository was last updated on October 10, 2026.

Source: affaan-m/ECC on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.