Agent skill

Secure Agent

by mathematic-inc in mathematic-inc/earl

Locks down an AI agent by configuring platform-level tool restrictions (deniedTools) and Earl network egress rules.

Apache-2.0Auto-check passedBackend & APIs

Install Secure Agent

skills CLI
$ npx skills add mathematic-inc/earl --skill secure-agent -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mathematic-inc/earl secure-agent --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mathematic-inc/earl.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/development/secure-agent .claude/skills/secure-agent && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
secure-agent
GitHub stars
113
Token cost
~2.1k tokens
SKILL.md length
925 words
Files
1
Skills in repo
4
Repo updated
First seen
Licence
Apache-2.0

At a glance

Locks down an AI agent by configuring platform-level tool restrictions (deniedTools) and Earl network egress rules.

  • Works in 5 steps: Check Coverage → Generate and Present Denylist → Apply Denylist → …
  • Backend & APIs work in your project
  • SKILL.md covers What This Does, Important Limitation, Platform Support and Step 1: Check Coverage, plus 6 more sections
  • Calls gh and curl

What it does

Secure Agent is an agent skill from mathematic-inc/earl. Locks down an AI agent by configuring platform-level tool restrictions (deniedTools) and Earl network egress rules. Use after Earl is working and templates are created, to make Earl's security guarantee enforceable rather than advisory.

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs. It works with Model Context Protocol. The repository describes itself as: Secure CLI proxy for AI agents — HCL-defined operation templates with OS keychain secrets, MCP integration, and prompt injection protection. The licence is Apache-2.0.

When your agent uses it

  • Backend & APIs work in your project

Example prompts

  • “Use the secure-agent skill to lock down an AI agent by configuring platform-level tool restrictions (deniedTools) and Earl network egress rules”
  • “/secure-agent”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Check Coverage
  2. Generate and Present Denylist
  3. Apply Denylist
  4. Verify
  5. Configure Egress Rules (Strongly Recommended)

What it can do on your machine

Read from SKILL.md and the folder at commit c56a45f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.anthropic.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Secure Agent loads about 2.1k tokens when it runs. Until then it costs about 62 tokens; SKILL.md has 925 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~62
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mathematic-inc/earl at commit c56a45f, republished under its Apache-2.0 licence (© mathematic-inc). 925 words, ~2,078 tokens.

Download SKILL.mdSave it as .claude/skills/secure-agent/SKILL.md (or your agent's skills folder).
name
secure-agent
description
Locks down an AI agent by configuring platform-level tool restrictions (deniedTools) and Earl network egress rules. Use after Earl is working and templates are created, to make Earl's security guarantee enforceable rather than advisory.

Secure Agent

After Earl is set up and working, this skill restricts the agent's ability to bypass Earl and make raw API/CLI calls directly. Without this step, CLAUDE.md is just a suggestion.

What This Does

  1. deniedTools: Blocks specific bash commands (curl, gh, stripe-cli, etc.) at the platform level for Claude Code. Agents cannot run these commands at all.
  2. Egress rules: Restricts which URLs Earl templates can contact, preventing Earl itself from being used as an open proxy.

Important Limitation

deniedTools pattern matching can be bypassed via alternative tools (python3 -c "import urllib...", node -e "fetch(...)", etc.). This blocks accidental or habitual CLI use — the common case. For stronger containment, pair with OS-level firewall rules or a network proxy.

Platform Support

PlatformMechanismHard restriction?
Claude CodedeniedTools in .claude/settings.jsonYes — platform enforced
Cursor.cursor/mcp.json or Cursor settings UIPartial — check Cursor docs for per-tool restrictions
Windsurf.windsurf/mcp.json or Windsurf settings UIPartial — check Windsurf docs for per-tool restrictions
Claude DesktopNo bash accessN/A
Non-MCP CLI agentsCLAUDE.md instructions onlyNo — advisory only

This skill primarily targets Claude Code. Instructions for other platforms are best-effort.


Step 1: Check Coverage

Only deny tools for services that have Earl templates. Denying a tool for a service with no Earl template would leave the agent unable to interact with that service at all.

bash
earl templates list --json

Note which providers are covered. Map each to the CLI tools to deny:

Earl template coversDeny these tools
githubBash(gh *), Bash(hub *)
stripeBash(stripe *)
slackBash(slack *)
openaiBash(openai *)
vercelBash(vercel *)
Any HTTP API templateBash(curl *), Bash(wget *), Bash(http *), Bash(httpie *)
Any SQL templateBash(psql *), Bash(mysql *), Bash(sqlite3 *)
Any gRPC templateBash(grpcurl *)

Do NOT deny Bash entirely. Earl's bash protocol and legitimate shell operations still need it.

Note on Bash(curl *) and Bash(wget *): Denying these also blocks all non-API curl uses — downloading binaries, health probes (curl http://localhost:8080/health), fetching install scripts, etc. If the agent legitimately needs curl for non-API tasks, add a narrow allowedTools override for those specific patterns, or use earl call instead for all HTTP operations.

Note on Bash(gh *): Denying gh also blocks all gh CLI uses that are not API calls: gh pr create, gh release upload, gh repo clone, branch management, etc. If the agent needs gh for repository operations that don't have Earl templates, add narrow exceptions or create templates for those commands before denying Bash(gh *).


Step 2: Generate and Present Denylist

Based on the covered providers, generate the deniedTools array. Show it to the user before applying anything:

"Based on your Earl templates, I'd add these restrictions to .claude/settings.json:

json
{
  "deniedTools": ["Bash(curl *)", "Bash(wget *)", "Bash(gh *)", "Bash(stripe *)"]
}

This blocks the listed tools for this agent in this project. Other projects are unaffected. Shall I apply this?"

Do not apply until the user explicitly approves.


Step 3: Apply Denylist

For Claude Code: read .claude/settings.json, merge the deniedTools array (do not overwrite other keys), write it back.

If deniedTools already exists, merge arrays — do not duplicate entries.


Show full SKILL.md (439 more words)Show less

Step 4: Verify

For Claude Code: Attempt to run a denied command:

bash
curl https://example.com

Claude Code will refuse to run this command. The "tool denied" or "not allowed" error message from Claude Code is the success signal — it means the denylist is active. You cannot distinguish success from failure by looking at the exit code; look at whether Claude Code blocked it before the shell ran it.

If Claude Code runs curl without blocking it, the deniedTools pattern syntax is wrong. Check the format against current Claude Code documentation (search "deniedTools settings" in the Claude Code docs or at https://docs.anthropic.com/en/docs/claude-code) — the exact pattern syntax may vary by version. Then re-apply with the corrected format.

For other platforms: Ask the user to attempt a denied command manually in their agent session and confirm it is blocked.

Test that Earl still works:

bash
earl templates list

Expected: succeeds and lists available templates (Earl is not in the denylist).


Without egress rules, Earl is an open proxy — any HTTP template with a parameterized URL can reach any public endpoint. Add [[network.allow]] rules to ~/.config/earl/config.toml (macOS/Linux) or %APPDATA%\earl\config.toml (Windows) to restrict which hosts Earl templates can contact.

Note: Egress rules are global — they apply to all projects using this Earl install. Earl does not currently support per-project config files.

For each provider template, add a rule:

toml
[[network.allow]]
hosts = ["api.github.com"]

[[network.allow]]
hosts = ["api.stripe.com"]

[[network.allow]]
hosts = ["api.slack.com", "slack.com"]

Security note on environments: If any template uses allow_environment_protocol_switching = true in its annotations, an environment override can silently switch protocols (e.g. from HTTP to bash). Review templates with this annotation carefully — a staging environment that switches to bash bypasses the HTTP egress rules above. Prefer vars.* for environment differences (e.g. different base URLs) over full protocol switching where possible.

After editing, verify:

bash
earl doctor

Earl doctor checks that the config is valid. Any [[network.allow]] parse errors will be reported.


What This Does Not Cover

  • Bash templates: The bash protocol runs user-defined scripts in Earl's sandbox. The denylist does not restrict what Earl's own bash protocol can do. Ensure bash templates explicitly set sandbox.network = false unless network access is required.
  • Agents without per-tool restriction: For non-Claude-Code agents, the CLAUDE.md instruction is the only constraint. This is advisory, not enforced.
  • Alternative interpreters: Python, Node, Ruby, and other interpreters are not blocked by a curl-specific denylist. Pair with OS-level firewall rules for stronger containment.

Next Steps

  • Earl is now the enforced channel for all covered API calls
  • To add egress rules for a new provider: add [[network.allow]] blocks to ~/.config/earl/config.toml
  • If the agent is blocked from a call it needs: add an Earl template for that service, or remove the specific deny rule for that tool
  • If something breaks: invoke troubleshoot-earl

© mathematic-inc, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/development/secure-agent of mathematic-inc/earl.

Open the folder on GitHubat commit c56a45f

Compare with similar skills

Secure Agent next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Secure Agent compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Secure Agent this skillmathematic-inc/earl113—~2.1kAutomated safety check: PassApache-2.0
Review Security ReportPrefectHQ/fastmcp28k—~1.2kAutomated safety check: PassApache-2.0
Tenuo Agent Authorizationtenuo-ai/tenuo101—~2.3kAutomated safety check: PassApache-2.0
OneCLI Gatewaynanocoai/nanoclaw31k—~856Automated safety check: PassMIT
Company Contact Findergooseworks-ai/goose-skills1.2k1 repos~2.7kAutomated safety check: PassMIT
Supabase Development and Debuggingsupabase/agent-skills2.7k3 repos~3.6kAutomated safety check: PassMIT

Similar skills

  • Review Security Report

    PrefectHQ/fastmcp

    Review FastMCP vulnerability reports before accepting, rejecting, patching, scoring, or publishing them.

    28k GitHub stars~1.2k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Add or retrofit Tenuo authorization for AI-agent tools and effects.

    101 GitHub stars~2.3k tokensUpdated today
    Backend & APIsAuto-check passed
  • OneCLI Gateway

    nanocoai/nanoclaw

    Explains how to call external APIs through the OneCLI proxy, which injects stored credentials into outgoing HTTPS requests so the agent never handles keys.

    31k GitHub stars~856 tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Company Contact Finder

    gooseworks-ai/goose-skills

    Find decision-makers at a specific company using Apollo, Crustdata, Fiber, and PDL people search via Gooseworks MCP.

    1.2k GitHub starsUsed in 1 repo~2.7k tokens
    Backend & APIsAuto-check passed
  • Official

    General Supabase skill for database, auth, Edge Functions, Realtime and storage work, plus client libraries, migrations, security audits, debugging and reading logs.

    2.7k GitHub starsUsed in 3 repos~3.6k tokens
    Backend & APIsAuto-check passed
  • OpenAPI to MCP Server

    mcp-use/mcp-use

    Turns an OpenAPI or Swagger spec into an MCP server with the mcp-use TypeScript SDK, mapping each operation to a tool, wiring auth, testing and deploying.

    11k GitHub stars~5.2k tokensUpdated yesterday
    Backend & APIsAuto-check passed

More from mathematic-inc/earl

  • Migrate To Earl

    mathematic-inc/earl

    Scans a codebase for raw API/CLI calls (curl, gh, stripe-cli, psql, grpcurl, etc.) and replaces them with Earl templates — one provider at a time.

    113 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Create Template

    mathematic-inc/earl

    Creates a new Earl HCL template for a specific API, database, or shell command.

    113 GitHub stars~2.8k tokensUpdated yesterday
    Auto-check passed
  • Earl

    mathematic-inc/earl

    A skill your agent uses when you need to call an API, run a database query, or execute a shell command via Earl.

    113 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed

Questions about Secure Agent

What does Secure Agent do?

Locks down an AI agent by configuring platform-level tool restrictions (deniedTools) and Earl network egress rules. Secure Agent is an agent skill from mathematic-inc/earl. Locks down an AI agent by configuring platform-level tool restrictions (deniedTools) and Earl network egress rules.

When should I use Secure Agent?

Secure Agent fits situations like: backend & APIs work in your project.

How do I install Secure Agent in Claude Code?

Run `npx skills add mathematic-inc/earl --skill secure-agent -a claude-code`. Or copy the skill folder (skills/development/secure-agent in mathematic-inc/earl) into .claude/skills/secure-agent in your project. Claude Code loads it when a task matches its description.

How do I install Secure Agent in Codex?

Run `npx skills add mathematic-inc/earl --skill secure-agent -a codex`. Or copy the skill folder (skills/development/secure-agent in mathematic-inc/earl) into .agents/skills/secure-agent in your project. Codex loads it when a task matches its description.

Can I use Secure Agent in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mathematic-inc/earl --skill secure-agent -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/secure-agent, .gemini/skills/secure-agent, .github/skills/secure-agent and .opencode/skills/secure-agent in your project.

What does Secure Agent need to run?

Going by SKILL.md and its folder, Secure Agent needs the command-line tools its instructions call (gh and curl). Our summary lists: Python 3.

Does Secure Agent access the network?

SKILL.md names 1 domain. As links in the text: docs.anthropic.com. This is read from the text; nothing was executed.

Is Secure Agent safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Secure Agent use?

Secure Agent is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Secure Agent use?

About 2.1k tokens (SKILL.md is roughly 8.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Secure Agent?

Skills that share tags, products or a category with Secure Agent: Review Security Report (PrefectHQ/fastmcp, 28k stars), Tenuo Agent Authorization (tenuo-ai/tenuo, 101 stars), OneCLI Gateway (nanocoai/nanoclaw, 31k stars) and Company Contact Finder (gooseworks-ai/goose-skills, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Secure Agent?

mathematic-inc (a GitHub organization) maintains it in mathematic-inc/earl, which has 113 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 6, 2026.

Source: mathematic-inc/earl on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.