Agent skill

Input Validation

by Archive228 in Archive228/loopkit

Validate and constrain untrusted input at the boundary. An agent skill from Archive228/loopkit.

MITAuto-check passed

Install Input Validation

skills CLI
$ npx skills add Archive228/loopkit --skill input-validation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Archive228/loopkit input-validation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Archive228/loopkit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/input-validation .claude/skills/input-validation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
input-validation
GitHub stars
755
Token cost
~222 tokens
SKILL.md length
98 words
Files
1
Skills in repo
52
Repo updated
First seen
Licence
MIT

At a glance

Validate and constrain untrusted input at the boundary. An agent skill from Archive228/loopkit.

  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Input Validation is an agent skill from Archive228/loopkit. Validate and constrain untrusted input at the boundary. Use on any handler that accepts external data.

Its SKILL.md is about 220 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: 33 battle-tested skills + minimal .claude harness for any coding agent (Claude Code, Cursor, Codex, Gemini CLI). The licence is MIT.

Example prompts

  • “/input-validation”

What it can do on your machine

Read from SKILL.md and the folder at commit 5ae033e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Input Validation loads about 222 tokens when it runs. Until then it costs about 30 tokens; SKILL.md has 98 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~30
When it runs · the whole SKILL.md, loaded when a task matches
~222

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Archive228/loopkit at commit 5ae033e, republished under its MIT licence (© Archive228). 98 words, ~222 tokens.

Download SKILL.mdSave it as .claude/skills/input-validation/SKILL.md (or your agent's skills folder).
name
input-validation
description
Validate and constrain untrusted input at the boundary. Use on any handler that accepts external data.
when_to_use
request bodies, query params, file uploads, webhook payloads, form data

Input Validation

Validate at the edge, before the data touches logic or storage.

  • Schema — type, required fields, allowed values. Reject unknown fields rather than ignoring them.
  • Bounds — string length, number ranges, array size. An unbounded input is a DoS and a memory bomb.
  • Format — emails, UUIDs, dates parsed and re-validated, not trusted as strings.
  • Files — size limit, type allowlist (check content, not just extension), no path traversal in names.
  • Reject with a clear 4xx and a message that says what's wrong — without leaking internals. Never trust "it comes from our own frontend". The request can come from anywhere.

© Archive228, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/input-validation of Archive228/loopkit.

Open the folder on GitHubat commit 5ae033e

Compare with similar skills

Input Validation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Input Validation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Input Validation this skillArchive228/loopkit755—~222Automated safety check: PassMIT
Search Inputthedaviddias/Front-End-Checklist74k—~402Automated safety check: PassMIT
Input Typesthedaviddias/Front-End-Checklist74k—~487Automated safety check: PassMIT
Paste Inputsthedaviddias/Front-End-Checklist74k—~443Automated safety check: PassMIT
Od Next Media Inputsnexu-io/open-design100k—~1.1kAutomated safety check: PassApache-2.0
Aria Input Field Namethedaviddias/Front-End-Checklist74k—~853Automated safety check: PassMIT

Similar skills

  • Search Input

    thedaviddias/Front-End-Checklist

    A skill your agent uses when reviewing templates, rendered HTML, or shared components related to Make search inputs accessible.

    74k GitHub stars~402 tokensUpdated yesterday
    Frontend & DesignAuto-check passed
  • Input Types

    thedaviddias/Front-End-Checklist

    A skill your agent uses when reviewing templates, rendered HTML, or shared components related to Use semantic input type attributes.

    74k GitHub stars~487 tokensUpdated yesterday
    Auto-check passed
  • Paste Inputs

    thedaviddias/Front-End-Checklist

    A skill your agent uses when reviewing rendered HTML, interactive components, or design-system patterns related to Allow pasting into form inputs.

    74k GitHub stars~443 tokensUpdated yesterday
    Frontend & DesignAuto-check passed
  • Od Next Media Inputs

    nexu-io/open-design

    Prepare required media inputs within an existing OD Next plan.

    100k GitHub stars~1.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Aria Input Field Name

    thedaviddias/Front-End-Checklist

    A skill your agent uses when applies to all <input (except type=hidden), <textarea, <select, and custom form widgets using role=textbox, role=combobox, role=spinbutton, role=searchbox, or…

    74k GitHub stars~853 tokensUpdated yesterday
    Frontend & DesignAuto-check passed
  • Resolve Inputs

    omnigent-ai/omnigent

    Select the Resolve mode, recover its input, check the workspace, and discover existing fixes.

    11k GitHub stars~2k tokensUpdated today
    Auto-check passed

More from Archive228/loopkit

All 52 skills in this repo
  • Hitl Escalate

    Archive228/loopkit

    Escalate blocked runs to a human via configured channel or fallback to BLOCKED.md and exit the loop.

    755 GitHub stars~1.2k tokensUpdated 2 mo ago
    Auto-check passed
  • Structured Output

    Archive228/loopkit

    Get JSON out of the model reliably. An agent skill from Archive228/loopkit.

    755 GitHub stars~830 tokensUpdated 2 mo ago
    Auto-check passed
  • Using Loopkit

    Archive228/loopkit

    A skill your agent uses when starting any conversation in a loopkit-enabled project - establishes how to find and use loopkit's 49 skills, requiring skill invocation before ANY response including…

    755 GitHub stars~1.4k tokensUpdated 2 mo ago
    Auto-check passed
  • Active Memory Reminder

    Archive228/loopkit

    Before compaction Loopkit extracts decisions into claude-decisions.json (machine-readable).

    755 GitHub stars~1.2k tokensUpdated 2 mo ago
    Auto-check passed
  • Eval Harness

    Archive228/loopkit

    Build a repeatable eval loop that grades agent output with an LLM judge, so prompt/skill changes get scored against a baseline instead of eyeballed.

    755 GitHub stars~876 tokensUpdated 2 mo ago
    Auto-check passed
  • Feature List JSON

    Archive228/loopkit

    Enumerate every end-to-end feature as strict JSON entries with passes:false, editable-passes-only discipline, and priority order.

    755 GitHub stars~1.2k tokensUpdated 2 mo ago
    Auto-check passed

Questions about Input Validation

What does Input Validation do?

Validate and constrain untrusted input at the boundary. An agent skill from Archive228/loopkit. Input Validation is an agent skill from Archive228/loopkit. Validate and constrain untrusted input at the boundary.

How do I install Input Validation in Claude Code?

Run `npx skills add Archive228/loopkit --skill input-validation -a claude-code`. Or copy the skill folder (skills/input-validation in Archive228/loopkit) into .claude/skills/input-validation in your project. Claude Code loads it when a task matches its description.

How do I install Input Validation in Codex?

Run `npx skills add Archive228/loopkit --skill input-validation -a codex`. Or copy the skill folder (skills/input-validation in Archive228/loopkit) into .agents/skills/input-validation in your project. Codex loads it when a task matches its description.

Can I use Input Validation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Archive228/loopkit --skill input-validation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/input-validation, .gemini/skills/input-validation, .github/skills/input-validation and .opencode/skills/input-validation in your project.

What does Input Validation need to run?

SKILL.md names no scripts, command-line tools or credentials: Input Validation is instructions for the agent only.

Does Input Validation access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Input Validation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Input Validation use?

Input Validation is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Input Validation use?

About 222 tokens (SKILL.md is roughly 888 characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Input Validation?

Skills that share tags, products or a category with Input Validation: Search Input (thedaviddias/Front-End-Checklist, 74k stars), Input Types (thedaviddias/Front-End-Checklist, 74k stars), Paste Inputs (thedaviddias/Front-End-Checklist, 74k stars) and Od Next Media Inputs (nexu-io/open-design, 100k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Input Validation?

Archive228 (a GitHub user) maintains it in Archive228/loopkit, which has 755 GitHub stars. The repository holds 52 skills in this directory. The repository was last updated on July 14, 2026.

Source: Archive228/loopkit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.