Security Guide
jnMetaCode/shellward
OpenClaw 安全部署指南 / Security deployment guide — help users secure their OpenClaw installation
Scan application source, agent skills, and MCP components; run penetration tests against scoped web test deployments, validate findings, and configure scan gates.
$ npx skills add first-fluke/oh-my-agent --skill oma-security -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install first-fluke/oh-my-agent oma-security --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/first-fluke/oh-my-agent.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/oma-security .claude/skills/oma-security && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "oma-security" agent skill from https://github.com/first-fluke/oh-my-agent/tree/main/skills/oma-security into .claude/skills/oma-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "oma-security", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/first-fluke/oh-my-agent/tree/main/skills/oma-securityType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add first-fluke/oh-my-agent --skill oma-security -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install first-fluke/oh-my-agent oma-security --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/first-fluke/oh-my-agent.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/oma-security .agents/skills/oma-security && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "oma-security" agent skill from https://github.com/first-fluke/oh-my-agent/tree/main/skills/oma-security into .agents/skills/oma-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "oma-security", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add first-fluke/oh-my-agent --skill oma-security -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install first-fluke/oh-my-agent oma-security --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/first-fluke/oh-my-agent.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/oma-security .cursor/skills/oma-security && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "oma-security" agent skill from https://github.com/first-fluke/oh-my-agent/tree/main/skills/oma-security into .cursor/skills/oma-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "oma-security", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/first-fluke/oh-my-agent.git --path skills/oma-security--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add first-fluke/oh-my-agent --skill oma-security -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install first-fluke/oh-my-agent oma-security --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/first-fluke/oh-my-agent.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/oma-security .gemini/skills/oma-security && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "oma-security" agent skill from https://github.com/first-fluke/oh-my-agent/tree/main/skills/oma-security into .gemini/skills/oma-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "oma-security", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install first-fluke/oh-my-agent oma-securityInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add first-fluke/oh-my-agent --skill oma-security -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/first-fluke/oh-my-agent.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/oma-security .github/skills/oma-security && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "oma-security" agent skill from https://github.com/first-fluke/oh-my-agent/tree/main/skills/oma-security into .github/skills/oma-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "oma-security", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add first-fluke/oh-my-agent --skill oma-security -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install first-fluke/oh-my-agent oma-security --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/first-fluke/oh-my-agent.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/oma-security .opencode/skills/oma-security && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "oma-security" agent skill from https://github.com/first-fluke/oh-my-agent/tree/main/skills/oma-security into .opencode/skills/oma-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "oma-security", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
oma-securityScan application source, agent skills, and MCP components; run penetration tests against scoped web test deployments, validate findings, and configure scan gates.
Oma Security is an agent skill from first-fluke/oh-my-agent. Scan application source, agent skills, and MCP components; run penetration tests against scoped web test deployments, validate findings, and configure scan gates. Use oma-qa for broad quality reviews and domain skills for remediation.
Its SKILL.md is about 3.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 37 other files, including reference files (for example `references/_shared/conditional/experiment-ledger.md`, `references/_shared/conditional/exploration-loop.md` and `references/_shared/conditional/quality-score.md`).
It sits in Security, covering Deployment. It works with Model Context Protocol. The repository describes itself as: Mechanical verification for AI coding agents — skills pack or full harness (stop-hook gates, artifact checks, independent judges). The licence is MIT.
10 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 268bb4a. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are yaml).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Oma Security loads about 3.9k tokens when it runs, and up to ~18k if it reads all its reference files. Until then it costs about 62 tokens; SKILL.md has 1,771 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from first-fluke/oh-my-agent at commit 268bb4a, republished under its MIT licence (© first-fluke). 1,771 words, ~3,877 tokens.
.claude/skills/oma-security/SKILL.md (or your agent's skills folder). This skill also uses 32 other files; get the full folder from GitHub.Run the selected security checks, retain their native evidence, independently validate candidates, and report findings and coverage on the recorded source or deployment identity.
oma-qa.oma-search.oma-architecture.oma-debug or the owning backend/frontend/mobile/infrastructure skill.target and target_type: source | skill | mcp | web_runtime; source/package paths are absolute.intent: setup | scan | diff | pentest | triage | validate | ci | troubleshoot.outputs:
- name: run
artifact: ".agents/results/security/*/run.json"
required: true
- name: findings
artifact: ".agents/results/security/*/findings.json"
required: true
- name: report
artifact: ".agents/results/security/*/report.md"
required: trueUse one unique .agents/results/security/<run-id>/ per invocation and check that directory explicitly; old matching files do not establish completion.
Keep raw outputs and logs under raw/<engine>/, verification evidence under evidence/, and stable references to native engine workspaces.
When web_runtime is selected, also require runtime.json; for ci, require gate.json.
Report confirmed findings, reviewed leads, unreviewed candidates, rejected claims, scope, skips, engine failures, budget stops, and evidence limits separately.
Load the chosen target/engine resource; load the findings contract when retaining or normalizing results.
Only load validation for triage/reproduction and CI guidance for a gate request.
Use an installed/pinned native interface; inspect its version and help before choosing flags.
Deepsec init can configure models and start AI review; do not treat it as free scaffolding or run it before the selected scope/spend is authorized.
Use native cost/duration controls verified against the installed engine; record when a hard bound cannot be enforced.
ARTEX uses a verified snapshot-specific UI/API or manual/external integration; it has no assumed scanner command.
Authorization, clarification, spend, build restrictions, and completion follow references/_shared/core/execution-policy.md.
Existing backend/scope/spend authorization persists. A key, login, or installed tool alone does not authorize paid calls or changed scope.
| Concrete target | Default engine | Alternative/additional operation |
|---|---|---|
| Application source or source diff | Deepsec | Cisco AI Deep SAST when explicitly selected or included in the authorized plan |
| Agent skill directory/package | Cisco Skill Scanner | Independent validation of candidates |
| MCP source/configuration/server | Cisco MCP Scanner | Only supported static/dynamic modes within scope |
Web test deployment (web_runtime, pentest) | ARTEX | Independent runtime replay of candidates |
| Bounded source/local reproduction | Cloudflare validation method | No external network or deployment traffic |
A general repository scan selects source; do not add skill/MCP/runtime scans by implication. A full source-plus-runtime audit includes ARTEX when a concrete web test deployment is provided; absent deployment leaves that stage pending. Use the user-named engine within its supported target/mode. No failed or empty result automatically selects another engine, model, backend, or paid analyzer. Cloudflare is a validation procedure, not evidence of superior detection accuracy. Keep its local-only proof separate from ARTEX's network-scoped runtime proof and Deepsec's static-only worker.
.deepsec/ state: preserve and resume it; never reinitialize to erase a failed or noisy run.planned and running during execution, then completed | partial | failed | skipped at final handoff; unresolved required work makes the run partial.| Failure | Recovery |
|---|---|
| Unsupported target, language, mode, or incomplete parse | Record the exact excluded/unscanned units; continue only other selected operations |
| Credentials, quota, refusal, timeout, or provider error | Save native receipts; follow the selected engine's resume procedure; preserve affected scope as unverified |
| Malformed/missing output or engine crash | Mark failed/partial with captured stderr/exit; do not create a successful empty findings result |
| Selected analyzer did not run or read the full target | Mark missing/partial coverage even when the tool exits 0 |
| New engine/backend/endpoint would change cost or scope | Reuse existing shared-policy authorization; resolve only the actual missing decision |
| No OS sandbox or trusted evidence promotion | Do not execute target-controlled code; keep the candidate's exact validation blocker |
| ARTEX snapshot/artifact, allowlist enforcement, or budget controls unavailable | Leave runtime pending/partial; do not assume an upstream image/release or substitute production |
| Runtime budget stop, unsuccessful attack, or incomplete exploration | Retain task and traffic receipts; report measured coverage and stop reason |
| Replay fails or evidence disagrees | Record the observation and counterevidence; failed reproduction alone does not refute the claim |
| Source/deployment identity changes | Preserve prior evidence; invalidate current confirmation and rerun affected checks |
completed: selected operations and required evidence review are accounted for on the recorded identity; remaining reviewed leads are explicit.partial: a selected operation, coverage unit, or required validation check remains unavailable/incomplete.failed: no usable requested scan result exists; retain failure evidence and the bounded recovery action.run.json with planned receipts before execution. For runtime, bind test URL/allowlist/accounts/effects/limits and deployment/session identity; record model/backend egress separately from target-network scope.pending_candidates.confirmed requires independent observed proof; static revalidation or ARTEX narrative alone is insufficient. Keep decisive missing facts as reviewed needs_validation leads; retain unreviewed candidates separately and mark partial coverage.run.json records targets, immutable or session identity, engine completion, scope, configuration/model/version, native exits, coverage, authorized limits, and gaps.
findings.json separates final reviewed records from pending candidates; severity, native confidence/verdict, independent validation, and reproduction are distinct.
Use validation: unreviewed | supported | refuted | inconclusive and reproduction: not_attempted | reproduced | not_reproduced | blocked.
proof_context is local_sandbox, authorized_runtime, or null when no proof occurred; status is confirmed, needs_validation, or rejected.
Assign normalized severity only to confirmed evidence; preserve engine-rated severity in provenance for every candidate.
Missing deployed revision restricts runtime proof to the observed deployment/session; it cannot confirm checked-out source or another environment.
JSON syntax/schema checks establish record format; reference/hash/identity checks and independent observed proof establish evidence. Report each check's actual result separately.
Keep raw originals unchanged and access-controlled; shared/normalized copies omit passwords, keys, cookies, authorization headers, and private user data.
resources/deepsec-setup.md (Deepsec setup or missing INFO.md).resources/deepsec-scanning.md (Deepsec source analysis).resources/deepsec-config.md (Deepsec configuration or troubleshooting).resources/deepsec-matchers.md (explicit matcher work).resources/cisco-source.md (Cisco AI Deep SAST selected).resources/skill-scanning.md (skill target selected).resources/mcp-scanning.md (MCP target selected).resources/artex.md (ARTEX or web-runtime target selected).resources/validation.md (triage/validation or candidate review).resources/findings-contract.md (results retained/normalized).resources/ci.md (CI requested).references/_shared/core/execution-policy.md (scope, spend, or completion decisions).references/_shared/core/context-loading.md (resource/injection decisions).© first-fluke, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 32 other files (references) in skills/oma-security of first-fluke/oh-my-agent.
Open the folder on GitHubat commit 268bb4a
Oma Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Oma Security this skillfirst-fluke/oh-my-agent | 1.3k | — | ~3.9k | Automated safety check: Pass | MIT | |
| Security GuidejnMetaCode/shellward | 140 | — | ~644 | Automated safety check: Warn | Apache-2.0 | |
| Canary Tripwire Responsedeonmenezes/mantishack | 503 | — | ~376 | Automated safety check: Pass | Apache-2.0 | |
| AWS Cdk Developmentzxkane/aws-skills | 367 | 2 repos | ~2.5k | Automated safety check: Pass | MIT | |
| Prepare Cloudflare Production DeploymentLubomirGeorgiev/cloudflare-workers-nextjs-saas-template | 786 | — | ~5.9k | Automated safety check: Notes | MIT | |
| Deploy Observabilityaliyun/alibabacloud-observability-mcp-server | 166 | — | ~2.6k | Automated safety check: Notes | None |
jnMetaCode/shellward
OpenClaw 安全部署指南 / Security deployment guide — help users secure their OpenClaw installation
deonmenezes/mantishack
What to do if a mantiscanary decoy tool ever shows up as tempting or gets called -- treat it as a security incident, not a normal tool result
zxkane/aws-skills
AWS Cloud Development Kit (CDK) expert for building cloud infrastructure with TypeScript/Python.
LubomirGeorgiev/cloudflare-workers-nextjs-saas-template
Source-of-truth runbook for preparing this Vinext Cloudflare Workers SaaS template for production deployment.
aliyun/alibabacloud-observability-mcp-server
Deploy, start, and update the Alibaba Cloud Observability MCP Server (阿里云可观测 MCP Server).
paperboytm/spool
Publish the complete Spool CLI release train: synchronized versions, npm packages, the GitHub release, and the matching production web deployment.
first-fluke/oh-my-agent
Decomposes a complex feature into tasks, dispatches parallel specialist agents with durable state, and supervises verification, QA review and retries.
first-fluke/oh-my-agent
Splits a complex feature into prioritized tasks, spawns specialist CLI subagents in parallel, tracks them through shared memory and verifies each result.
first-fluke/oh-my-agent
Evaluates system boundaries and tradeoffs and writes architecture recommendations, option comparisons or ADRs, with a Mermaid diagram when structure changes.
first-fluke/oh-my-agent
Explores goals, constraints and alternative designs one question at a time and saves an approved design document before any planning or coding starts.
first-fluke/oh-my-agent
Coordinate assigned specialist tasks and handoffs manually. An agent skill from first-fluke/oh-my-agent.
first-fluke/oh-my-agent
Generate raster images or reference-guided variations through the OMA image CLI.
Works with
Categories
Scan application source, agent skills, and MCP components; run penetration tests against scoped web test deployments, validate findings, and configure scan gates. Oma Security is an agent skill from first-fluke/oh-my-agent. Scan application source, agent skills, and MCP components; run penetration tests against scoped web test deployments, validate findings, and configure scan gates.
Oma Security fits situations like: tasks that involve Deployment.
Run `npx skills add first-fluke/oh-my-agent --skill oma-security -a claude-code`. Or copy the skill folder (skills/oma-security in first-fluke/oh-my-agent) into .claude/skills/oma-security in your project. Claude Code loads it when a task matches its description.
Run `npx skills add first-fluke/oh-my-agent --skill oma-security -a codex`. Or copy the skill folder (skills/oma-security in first-fluke/oh-my-agent) into .agents/skills/oma-security in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add first-fluke/oh-my-agent --skill oma-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/oma-security, .gemini/skills/oma-security, .github/skills/oma-security and .opencode/skills/oma-security in your project.
SKILL.md names no scripts, command-line tools or credentials: Oma Security is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Oma Security is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.9k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 14k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Oma Security: Security Guide (jnMetaCode/shellward, 140 stars), Canary Tripwire Response (deonmenezes/mantishack, 503 stars), AWS Cdk Development (zxkane/aws-skills, 367 stars) and Prepare Cloudflare Production Deployment (LubomirGeorgiev/cloudflare-workers-nextjs-saas-template, 786 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
first-fluke (a GitHub organization) maintains it in first-fluke/oh-my-agent, which has 1,336 GitHub stars. The repository holds 57 skills in this directory. The repository was last updated on October 10, 2026.
Source: first-fluke/oh-my-agent on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.