AI LLM Agent Security
zhaji2333/CkSKILLS
当目标为 LLM 应用/Chatbot/智能客服/AI 助手/Copilot/Agent/RAG 知识库/多模态模型,或发现用户输入进入大模型提示、工具调用、知识库检索、对话记忆、文件解析,或需要测试提示词注入/越狱逃逸/System Prompt 泄露/训练数据与敏感信息泄露/RAG 检索污染/Agent 记忆污染/工具滥用与命令执行/SSRF/沙箱逃逸时调用。负责 OWASP LLM…
覆盖工具 allow/ask/deny、四种 permission mode、审批持久化、Workspace/Hook Trust、敏感文件以及 Hook/Browser 网络边界。
$ npx skills add echoVic/blade-code --skill knowledge-permissions-and-workspace-trust -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install echoVic/blade-code knowledge-permissions-and-workspace-trust --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/echoVic/blade-code.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.trae/knowledges/workspace-policy-and-shared-foundations/permissions-and-workspace-trust .claude/skills/knowledge-permissions-and-workspace-trust && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "knowledge-permissions-and-workspace-trust" agent skill from https://github.com/echoVic/blade-code/tree/main/.trae/knowledges/workspace-policy-and-shared-foundations/permissions-and-workspace-trust into .claude/skills/knowledge-permissions-and-workspace-trust/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "knowledge-permissions-and-workspace-trust", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/echoVic/blade-code/tree/main/.trae/knowledges/workspace-policy-and-shared-foundations/permissions-and-workspace-trustType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add echoVic/blade-code --skill knowledge-permissions-and-workspace-trust -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install echoVic/blade-code knowledge-permissions-and-workspace-trust --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/echoVic/blade-code.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.trae/knowledges/workspace-policy-and-shared-foundations/permissions-and-workspace-trust .agents/skills/knowledge-permissions-and-workspace-trust && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "knowledge-permissions-and-workspace-trust" agent skill from https://github.com/echoVic/blade-code/tree/main/.trae/knowledges/workspace-policy-and-shared-foundations/permissions-and-workspace-trust into .agents/skills/knowledge-permissions-and-workspace-trust/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "knowledge-permissions-and-workspace-trust", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add echoVic/blade-code --skill knowledge-permissions-and-workspace-trust -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install echoVic/blade-code knowledge-permissions-and-workspace-trust --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/echoVic/blade-code.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.trae/knowledges/workspace-policy-and-shared-foundations/permissions-and-workspace-trust .cursor/skills/knowledge-permissions-and-workspace-trust && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "knowledge-permissions-and-workspace-trust" agent skill from https://github.com/echoVic/blade-code/tree/main/.trae/knowledges/workspace-policy-and-shared-foundations/permissions-and-workspace-trust into .cursor/skills/knowledge-permissions-and-workspace-trust/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "knowledge-permissions-and-workspace-trust", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/echoVic/blade-code.git --path .trae/knowledges/workspace-policy-and-shared-foundations/permissions-and-workspace-trust--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add echoVic/blade-code --skill knowledge-permissions-and-workspace-trust -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install echoVic/blade-code knowledge-permissions-and-workspace-trust --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/echoVic/blade-code.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.trae/knowledges/workspace-policy-and-shared-foundations/permissions-and-workspace-trust .gemini/skills/knowledge-permissions-and-workspace-trust && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "knowledge-permissions-and-workspace-trust" agent skill from https://github.com/echoVic/blade-code/tree/main/.trae/knowledges/workspace-policy-and-shared-foundations/permissions-and-workspace-trust into .gemini/skills/knowledge-permissions-and-workspace-trust/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "knowledge-permissions-and-workspace-trust", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install echoVic/blade-code knowledge-permissions-and-workspace-trustInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add echoVic/blade-code --skill knowledge-permissions-and-workspace-trust -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/echoVic/blade-code.git skills-src && mkdir -p .github/skills && cp -r skills-src/.trae/knowledges/workspace-policy-and-shared-foundations/permissions-and-workspace-trust .github/skills/knowledge-permissions-and-workspace-trust && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "knowledge-permissions-and-workspace-trust" agent skill from https://github.com/echoVic/blade-code/tree/main/.trae/knowledges/workspace-policy-and-shared-foundations/permissions-and-workspace-trust into .github/skills/knowledge-permissions-and-workspace-trust/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "knowledge-permissions-and-workspace-trust", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add echoVic/blade-code --skill knowledge-permissions-and-workspace-trust -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install echoVic/blade-code knowledge-permissions-and-workspace-trust --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/echoVic/blade-code.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.trae/knowledges/workspace-policy-and-shared-foundations/permissions-and-workspace-trust .opencode/skills/knowledge-permissions-and-workspace-trust && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "knowledge-permissions-and-workspace-trust" agent skill from https://github.com/echoVic/blade-code/tree/main/.trae/knowledges/workspace-policy-and-shared-foundations/permissions-and-workspace-trust into .opencode/skills/knowledge-permissions-and-workspace-trust/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "knowledge-permissions-and-workspace-trust", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
knowledge-permissions-and-workspace-trust覆盖工具 allow/ask/deny、四种 permission mode、审批持久化、Workspace/Hook Trust、敏感文件以及 Hook/Browser 网络边界。
Knowledge Permissions And Workspace Trust is an agent skill from echoVic/blade-code. 覆盖工具 allow/ask/deny、四种 permission mode、审批持久化、Workspace/Hook Trust、敏感文件以及 Hook/Browser 网络边界。 使用时机:修改工具授权、排查为何调用被自动批准或拒绝、增加项目级可执行资源、处理信任继承、SSRF 或敏感路径。 不包含:配置文件通用合并见 layered-configuration-and-runtime-settings,工具执行阶段与并发见 tool-and-automation-platform/tool-execution-pipeline。 关键词:PermissionChecker, PermissionResolver, ToolApprovalController, WorkspaceTrustService, HookTrustService, SensitiveFileDetector, YOLO, PLAN。
Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Computer vision and Web application vulnerabilities. The repository describes itself as: AI-powered CLI coding agent with 20+ built-in tools, MCP support, and multi-model providers. The licence is MIT.
Read from SKILL.md and the folder at commit 30f8684. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Knowledge Permissions And Workspace Trust loads about 1.8k tokens when it runs. Until then it costs about 114 tokens; SKILL.md has 447 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from echoVic/blade-code at commit 30f8684, republished under its MIT licence (© echoVic). 447 words, ~1,776 tokens.
.claude/skills/knowledge-permissions-and-workspace-trust/SKILL.md (or your agent's skills folder).权限系统先把工具调用归一化成规则签名,再应用运行模式、Session 审批和路径安全覆盖;Workspace Trust 则在资源加载前决定仓库控制的配置、命令和指令是否可见,外部 Hook 还需要独立摘要信任。
packages/cli/src/config/PermissionChecker.ts — allow/ask/deny 规则和工具签名匹配packages/cli/src/tools/execution/PermissionResolver.ts — 模式、审计 Agent、Session 记忆和敏感路径覆盖packages/cli/src/tools/execution/ToolApprovalController.ts — 串行审批、Hook 审批和 project/session scopepackages/cli/src/tools/execution/ToolExecutionGuards.ts — CLI 白黑名单与 worktree 边界packages/cli/src/tools/validation/SensitiveFileDetector.ts — 凭据、环境文件和敏感目录分类packages/cli/src/security/WorkspaceIdentity.ts — canonical project 与 linked worktree trust rootpackages/cli/src/security/WorkspaceTrustService.ts — 项目来源审阅、继承决策和安全存储packages/cli/src/hooks/HookTrustService.ts — 外部 Hook 配置摘要信任packages/cli/src/hooks/HttpHookSecurity.ts — Hook URL 协议和内网限制packages/cli/src/browser/BrowserSecurity.ts — Browser origin、凭据控件和公开 URL 脱敏PermissionChecker.check() — 规则级 deny > allow > ask > default askPermissionResolver.resolveRulePermission() — 审计 Agent、permission mode、Session 记忆和敏感路径的组合入口resolvePermissionDecision() — 规则结果与 PreToolUse Hook 决策的收紧合并WorkspaceTrustService.getStatus() — 计算 not_required | trusted | untrusted | errorHookTrustService.getStatus() — 依据外部 Hook canonical digest 判断 trusted | modified| 工具/规则条件 | default | autoEdit | plan | yolo |
|---|---|---|---|---|
| 未匹配的 ReadOnly | 自动允许 | 自动允许 | 自动允许 | 自动允许 |
| 未匹配的 Write | 请求确认 | 自动允许 | 拒绝 | 自动允许 |
| 未匹配的 Execute | 请求确认 | 请求确认 | 拒绝 | 自动允许 |
| 显式 allow 的 Write/Execute | 允许 | 允许 | 仍拒绝 | 允许 |
| 显式 deny 的普通工具调用 | 拒绝 | 拒绝 | 拒绝 | 当前实现先被模式改写为允许 |
| verification/review Agent 的写入或变异命令 | 拒绝 | 拒绝 | 拒绝 | 在模式覆盖前拒绝 |
| 中高敏感文件路径 | allow 会降为 ask,其余高敏感请求拒绝 | allow 会降为 ask,其余高敏感请求拒绝 | 写操作先拒绝 | 模式 allow 仍会降为 ask |
packages/cli/src/tools/execution/ — 每次工具调用的规则、Hook、审批和 safety overridepackages/cli/src/agent/runtime/SessionRuntime.ts — Session 权限模式恢复与 workspace 规则装配packages/cli/src/config/ConfigManager.ts — 可信项目权限、环境和可执行配置的过滤packages/cli/src/plugins/ — 未信任项目的插件发现和启用阻断packages/cli/src/skills/ 与 packages/cli/src/slash-commands/custom/ — 项目 Skill/命令的 trust gatepackages/cli/src/hooks/ — Folder Trust 之外的外部 Hook 摘要信任和 HTTP 安全packages/cli/src/browser/ — URL/origin 分类、凭据控件和远端副作用审批packages/cli/src/server/routes/permission.ts 与 packages/cli/src/server/routes/workspaceTrust.ts — Web 审批和信任操作PermissionResolver 在普通工具路径中先处理 yolo,因此会把 PermissionChecker 的显式 deny 改写为 allow;之后只有 Hook 或路径 safety override 能再次收紧,不能根据旧的辅助测试假定 deny 一定高于 yolo (packages/cli/src/tools/execution/PermissionResolver.ts, packages/cli/tests/unit/config-security/permissions/permission-modes.test.ts)packages/cli/src/tools/execution/PermissionResolver.ts)packages/cli/src/tools/execution/ToolExecutor.ts)packages/cli/src/tools/execution/PermissionResolver.ts, packages/cli/tests/unit/tooling/tools/execution/permission-resolver.test.ts)confirmationHandler 时,ask 不是隐式允许;除 yolo 外会返回结构化权限拒绝 (packages/cli/src/tools/execution/ToolApprovalController.ts).blade/settings.local.json,而不是服务器启动 cwd;工具没有 abstractPermissionRule() 或返回空串时不得持久化宽泛授权 (packages/cli/src/tools/execution/ToolApprovalController.ts, git:7b34bd7e)permissionSignature,参数变化会形成新签名并再次审批;project scope 才会写可复用抽象规则 (packages/cli/src/tools/execution/ToolApprovalController.ts, packages/cli/src/tools/execution/SessionApprovalStore.ts)modified (packages/cli/src/security/WorkspaceTrustService.ts, packages/cli/src/hooks/HookTrustService.ts)packages/cli/src/security/WorkspaceIdentity.ts)0600 原子写 (packages/cli/src/security/WorkspaceTrustService.ts)packages/cli/src/hooks/HttpHookSecurity.ts)[redacted];日志或审批预览不应绕过 projectBrowserUrl() 输出原始查询参数 (packages/cli/src/browser/BrowserSecurity.ts)packages/cli/src/tools/execution/ToolExecutor.ts)packages/cli/src/security/WorkspaceTrustService.ts)packages/cli/src/security/WorkspaceTrustService.ts)packages/cli/src/tools/execution/PermissionResolver.ts)packages/cli/src/hooks/HookTrustService.ts, git:a172a7c)packages/cli/src/security/WorkspaceIdentity.ts, packages/cli/src/security/WorkspaceTrustService.ts, git:dff75aca, git:47ca3370)not_required;存在敏感来源但无有效决策时为 untrusted;读取 trust store 失败时为 error,后二者均不得加载项目执行资源 (packages/cli/src/security/WorkspaceTrustService.ts)disableAllHooks=true 还可作为单向收紧生效 (packages/cli/src/config/ConfigManager.ts)packages/cli/src/tools/execution/PermissionResolver.ts)expectedOrigin,页面跳转后不能复用旧快照权限 (packages/cli/src/browser/BrowserSecurity.ts, packages/cli/src/tools/execution/ToolApprovalController.ts)packages/cli/src/security/reloadWorkspaceTrust.ts, packages/cli/tests/unit/security/reload-workspace-trust.test.ts)© echoVic, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .trae/knowledges/workspace-policy-and-shared-foundations/permissions-and-workspace-trust of echoVic/blade-code.
Open the folder on GitHubat commit 30f8684
Knowledge Permissions And Workspace Trust next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Knowledge Permissions And Workspace Trust this skillechoVic/blade-code | 181 | — | ~1.8k | Automated safety check: Pass | MIT | |
| AI LLM Agent Securityzhaji2333/CkSKILLS | 114 | — | ~4.7k | Automated safety check: Warn | MIT | |
| Hunt LLM AIelementalsouls/Claude-BugHunter | 4.8k | — | ~4k | Automated safety check: Warn | MIT | |
| Moai Ref LLM Securitymodu-ai/moai-adk | 1.2k | — | ~4.5k | Automated safety check: Pass | Apache-2.0 | |
| Hunt LLMEncod3d-Sec/TORCH | 329 | — | ~1.7k | Automated safety check: Pass | MIT | |
| Security And Hardeningpenpot/penpot | 61k | 6 repos | ~4.7k | Automated safety check: Notes | MPL-2.0 |
zhaji2333/CkSKILLS
当目标为 LLM 应用/Chatbot/智能客服/AI 助手/Copilot/Agent/RAG 知识库/多模态模型,或发现用户输入进入大模型提示、工具调用、知识库检索、对话记忆、文件解析,或需要测试提示词注入/越狱逃逸/System Prompt 泄露/训练数据与敏感信息泄露/RAG 检索污染/Agent 记忆污染/工具滥用与命令执行/SSRF/沙箱逃逸时调用。负责 OWASP LLM…
elementalsouls/Claude-BugHunter
Hunt LLM/AI feature bugs — prompt injection, indirect injection, exfiltration via tool-use/markdown, ASCII smuggling, agentic AI security (OWASP Agentic Apps 2026, ASI01-ASI10).
modu-ai/moai-adk
AI/LLM defensive security reference: prompt-injection defense, OWASP LLM Top 10 defensive mapping, MCP and agentic tool-call hardening, training-data poisoning detection, model-output validation and…
Encod3d-Sec/TORCH
LLM / AI application attack hunting - prompt injection (direct + indirect), excessive agency, insecure output handling, system-prompt + data leakage.
penpot/penpot
Hardens code against vulnerabilities. An agent skill from penpot/penpot.
eigent-ai/eigent
Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.
echoVic/blade-code
Base64 编解码工具,支持编码/解码文本、JSON、二进制文件,自动检测格式,支持批量处理. An agent skill from echoVic/blade-code.
echoVic/blade-code
Review frontend code for best practices, bugs, and improvements.
echoVic/blade-code
Explore and summarize popular GitHub projects. An agent skill from echoVic/blade-code.
echoVic/blade-code
覆盖 Session 级 LSP 配置快照、stdio 进程、文档同步、语义查询、诊断回注、崩溃恢复 和子 Session 继承。进入条件:新增语言服务器、修改 LSP 工具、排查诊断缺失/重复、 处理 worktree 或 ACP 差异、修复进程泄漏或 transport 代际问题。不包含:VS Code 扩展桥接(见…
echoVic/blade-code
覆盖 SkillRegistry、SKILL.md 延迟加载、自定义命令 Markdown 解析、来源覆盖、插件 命名空间、Session 快照和模型/用户调用入口。进入条件:新增 Skill 或命令字段、调整 发现优先级、调试 /command 或 Skill 工具、修改 Prompt 元数据或消费者集成。不包含: 插件安装生命周期(见…
echoVic/blade-code
Covers 领域能力如何包装成内置工具、getBuiltinTools 的 Session 依赖注入、ToolSearch 延迟激活,以及 Goal/Task/Team/Plan/Skill/LSP/MCP/Web/Config/Worktree 适配边界。
Categories
覆盖工具 allow/ask/deny、四种 permission mode、审批持久化、Workspace/Hook Trust、敏感文件以及 Hook/Browser 网络边界。. Knowledge Permissions And Workspace Trust is an agent skill from echoVic/blade-code.
Knowledge Permissions And Workspace Trust fits situations like: tasks that involve Computer vision; tasks that involve Web application vulnerabilities.
Run `npx skills add echoVic/blade-code --skill knowledge-permissions-and-workspace-trust -a claude-code`. Or copy the skill folder (.trae/knowledges/workspace-policy-and-shared-foundations/permissions-and-workspace-trust in echoVic/blade-code) into .claude/skills/knowledge-permissions-and-workspace-trust in your project. Claude Code loads it when a task matches its description.
Run `npx skills add echoVic/blade-code --skill knowledge-permissions-and-workspace-trust -a codex`. Or copy the skill folder (.trae/knowledges/workspace-policy-and-shared-foundations/permissions-and-workspace-trust in echoVic/blade-code) into .agents/skills/knowledge-permissions-and-workspace-trust in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add echoVic/blade-code --skill knowledge-permissions-and-workspace-trust -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/knowledge-permissions-and-workspace-trust, .gemini/skills/knowledge-permissions-and-workspace-trust, .github/skills/knowledge-permissions-and-workspace-trust and .opencode/skills/knowledge-permissions-and-workspace-trust in your project.
SKILL.md names no scripts, command-line tools or credentials: Knowledge Permissions And Workspace Trust is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Knowledge Permissions And Workspace Trust is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.8k tokens (SKILL.md is roughly 7.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Knowledge Permissions And Workspace Trust: AI LLM Agent Security (zhaji2333/CkSKILLS, 114 stars), Hunt LLM AI (elementalsouls/Claude-BugHunter, 4.8k stars), Moai Ref LLM Security (modu-ai/moai-adk, 1.2k stars) and Hunt LLM (Encod3d-Sec/TORCH, 329 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
echoVic (a GitHub user) maintains it in echoVic/blade-code, which has 181 GitHub stars. The repository holds 38 skills in this directory. The repository was last updated on September 27, 2026.
Source: echoVic/blade-code on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.