Install the "secure-agent" agent skill from https://github.com/mathematic-inc/earl/tree/main/skills/development/secure-agent into .claude/skills/secure-agent/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secure-agent", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add mathematic-inc/earl --skill secure-agent -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "secure-agent" agent skill from https://github.com/mathematic-inc/earl/tree/main/skills/development/secure-agent into .agents/skills/secure-agent/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secure-agent", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add mathematic-inc/earl --skill secure-agent -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "secure-agent" agent skill from https://github.com/mathematic-inc/earl/tree/main/skills/development/secure-agent into .cursor/skills/secure-agent/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secure-agent", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add mathematic-inc/earl --skill secure-agent -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "secure-agent" agent skill from https://github.com/mathematic-inc/earl/tree/main/skills/development/secure-agent into .gemini/skills/secure-agent/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secure-agent", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add mathematic-inc/earl --skill secure-agent -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "secure-agent" agent skill from https://github.com/mathematic-inc/earl/tree/main/skills/development/secure-agent into .github/skills/secure-agent/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secure-agent", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add mathematic-inc/earl --skill secure-agent -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "secure-agent" agent skill from https://github.com/mathematic-inc/earl/tree/main/skills/development/secure-agent into .opencode/skills/secure-agent/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secure-agent", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
secure-agent
GitHub stars
113
Token cost
~2.1k tokens
SKILL.md length
925 words
Files
1
Skills in repo
4
Repo updated
First seen
Licence
Apache-2.0
At a glance
Locks down an AI agent by configuring platform-level tool restrictions (deniedTools) and Earl network egress rules.
Works in 5 steps: Check Coverage → Generate and Present Denylist → Apply Denylist → …
Backend & APIs work in your project
SKILL.md covers What This Does, Important Limitation, Platform Support and Step 1: Check Coverage, plus 6 more sections
Calls gh and curl
What it does
Secure Agent is an agent skill from mathematic-inc/earl. Locks down an AI agent by configuring platform-level tool restrictions (deniedTools) and Earl network egress rules. Use after Earl is working and templates are created, to make Earl's security guarantee enforceable rather than advisory.
Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs. It works with Model Context Protocol. The repository describes itself as: Secure CLI proxy for AI agents — HCL-defined operation templates with OS keychain secrets, MCP integration, and prompt injection protection. The licence is Apache-2.0.
When your agent uses it
Backend & APIs work in your project
Example prompts
“Use the secure-agent skill to lock down an AI agent by configuring platform-level tool restrictions (deniedTools) and Earl network egress rules”
“/secure-agent”
Requirements
Python 3
Workflow steps
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit c56a45f. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
Shell commands in SKILL.md call:
gh
curl
From the folder's file list and the shell code blocks in SKILL.md.
Network
Links to these hosts (documentation or services it may open):
docs.anthropic.com
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
Secure Agent loads about 2.1k tokens when it runs. Until then it costs about 62 tokens; SKILL.md has 925 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~62
When it runs· the whole SKILL.md, loaded when a task matches
~2.1k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check passed
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Download SKILL.mdSave it as .claude/skills/secure-agent/SKILL.md (or your agent's skills folder).
name
secure-agent
description
Locks down an AI agent by configuring platform-level tool restrictions (deniedTools) and Earl network egress rules. Use after Earl is working and templates are created, to make Earl's security guarantee enforceable rather than advisory.
Secure Agent
After Earl is set up and working, this skill restricts the agent's ability to bypass Earl
and make raw API/CLI calls directly. Without this step, CLAUDE.md is just a suggestion.
What This Does
deniedTools: Blocks specific bash commands (curl, gh, stripe-cli, etc.) at the
platform level for Claude Code. Agents cannot run these commands at all.
Egress rules: Restricts which URLs Earl templates can contact, preventing Earl itself
from being used as an open proxy.
Important Limitation
deniedTools pattern matching can be bypassed via alternative tools (python3 -c "import urllib...", node -e "fetch(...)", etc.). This blocks accidental or habitual CLI use — the
common case. For stronger containment, pair with OS-level firewall rules or a network proxy.
Platform Support
Platform
Mechanism
Hard restriction?
Claude Code
deniedTools in .claude/settings.json
Yes — platform enforced
Cursor
.cursor/mcp.json or Cursor settings UI
Partial — check Cursor docs for per-tool restrictions
Windsurf
.windsurf/mcp.json or Windsurf settings UI
Partial — check Windsurf docs for per-tool restrictions
Claude Desktop
No bash access
N/A
Non-MCP CLI agents
CLAUDE.md instructions only
No — advisory only
This skill primarily targets Claude Code. Instructions for other platforms are best-effort.
Step 1: Check Coverage
Only deny tools for services that have Earl templates. Denying a tool for a service with no
Earl template would leave the agent unable to interact with that service at all.
bash
earl templates list --json
Note which providers are covered. Map each to the CLI tools to deny:
Do NOT deny Bash entirely. Earl's bash protocol and legitimate shell operations still
need it.
Note on Bash(curl *) and Bash(wget *): Denying these also blocks all non-API curl
uses — downloading binaries, health probes (curl http://localhost:8080/health), fetching
install scripts, etc. If the agent legitimately needs curl for non-API tasks, add a narrow
allowedTools override for those specific patterns, or use earl call instead for all
HTTP operations.
Note on Bash(gh *): Denying gh also blocks all gh CLI uses that are not API calls:
gh pr create, gh release upload, gh repo clone, branch management, etc. If the agent
needs gh for repository operations that don't have Earl templates, add narrow exceptions or
create templates for those commands before denying Bash(gh *).
Step 2: Generate and Present Denylist
Based on the covered providers, generate the deniedTools array. Show it to the user before
applying anything:
"Based on your Earl templates, I'd add these restrictions to .claude/settings.json:
This blocks the listed tools for this agent in this project. Other projects are unaffected.
Shall I apply this?"
Do not apply until the user explicitly approves.
Step 3: Apply Denylist
For Claude Code: read .claude/settings.json, merge the deniedTools array (do not overwrite
other keys), write it back.
If deniedTools already exists, merge arrays — do not duplicate entries.
Show full SKILL.md (439 more words)Show less
Step 4: Verify
For Claude Code: Attempt to run a denied command:
bash
curl https://example.com
Claude Code will refuse to run this command. The "tool denied" or "not allowed" error message
from Claude Code is the success signal — it means the denylist is active. You cannot
distinguish success from failure by looking at the exit code; look at whether Claude Code
blocked it before the shell ran it.
If Claude Code runs curl without blocking it, the deniedTools pattern syntax is wrong.
Check the format against current Claude Code documentation (search "deniedTools settings" in
the Claude Code docs or at https://docs.anthropic.com/en/docs/claude-code) — the exact pattern
syntax may vary by version. Then re-apply with the corrected format.
For other platforms: Ask the user to attempt a denied command manually in their agent
session and confirm it is blocked.
Test that Earl still works:
bash
earl templates list
Expected: succeeds and lists available templates (Earl is not in the denylist).
Without egress rules, Earl is an open proxy — any HTTP template with a parameterized URL can
reach any public endpoint. Add [[network.allow]] rules to
~/.config/earl/config.toml (macOS/Linux) or %APPDATA%\earl\config.toml (Windows)
to restrict which hosts Earl templates can contact.
Note: Egress rules are global — they apply to all projects using this Earl install.
Earl does not currently support per-project config files.
Security note on environments: If any template uses allow_environment_protocol_switching = true in its annotations, an environment override can silently switch protocols (e.g. from
HTTP to bash). Review templates with this annotation carefully — a staging environment that
switches to bash bypasses the HTTP egress rules above. Prefer vars.* for environment
differences (e.g. different base URLs) over full protocol switching where possible.
After editing, verify:
bash
earl doctor
Earl doctor checks that the config is valid. Any [[network.allow]] parse errors will be
reported.
What This Does Not Cover
Bash templates: The bash protocol runs user-defined scripts in Earl's sandbox. The
denylist does not restrict what Earl's own bash protocol can do. Ensure bash templates
explicitly set sandbox.network = false unless network access is required.
Agents without per-tool restriction: For non-Claude-Code agents, the CLAUDE.md instruction
is the only constraint. This is advisory, not enforced.
Alternative interpreters: Python, Node, Ruby, and other interpreters are not blocked by
a curl-specific denylist. Pair with OS-level firewall rules for stronger containment.
Next Steps
Earl is now the enforced channel for all covered API calls
To add egress rules for a new provider: add [[network.allow]] blocks to
~/.config/earl/config.toml
If the agent is blocked from a call it needs: add an Earl template for that service, or
remove the specific deny rule for that tool
Secure Agent next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Explains how to call external APIs through the OneCLI proxy, which injects stored credentials into outgoing HTTPS requests so the agent never handles keys.
General Supabase skill for database, auth, Edge Functions, Realtime and storage work, plus client libraries, migrations, security audits, debugging and reading logs.
Turns an OpenAPI or Swagger spec into an MCP server with the mcp-use TypeScript SDK, mapping each operation to a tool, wiring auth, testing and deploying.
Locks down an AI agent by configuring platform-level tool restrictions (deniedTools) and Earl network egress rules. Secure Agent is an agent skill from mathematic-inc/earl. Locks down an AI agent by configuring platform-level tool restrictions (deniedTools) and Earl network egress rules.
When should I use Secure Agent?
Secure Agent fits situations like: backend & APIs work in your project.
How do I install Secure Agent in Claude Code?
Run `npx skills add mathematic-inc/earl --skill secure-agent -a claude-code`. Or copy the skill folder (skills/development/secure-agent in mathematic-inc/earl) into .claude/skills/secure-agent in your project. Claude Code loads it when a task matches its description.
How do I install Secure Agent in Codex?
Run `npx skills add mathematic-inc/earl --skill secure-agent -a codex`. Or copy the skill folder (skills/development/secure-agent in mathematic-inc/earl) into .agents/skills/secure-agent in your project. Codex loads it when a task matches its description.
Can I use Secure Agent in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mathematic-inc/earl --skill secure-agent -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/secure-agent, .gemini/skills/secure-agent, .github/skills/secure-agent and .opencode/skills/secure-agent in your project.
What does Secure Agent need to run?
Going by SKILL.md and its folder, Secure Agent needs the command-line tools its instructions call (gh and curl). Our summary lists: Python 3.
Does Secure Agent access the network?
SKILL.md names 1 domain. As links in the text: docs.anthropic.com. This is read from the text; nothing was executed.
Is Secure Agent safe to install?
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
What licence does Secure Agent use?
Secure Agent is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does Secure Agent use?
About 2.1k tokens (SKILL.md is roughly 8.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
What are the alternatives to Secure Agent?
Skills that share tags, products or a category with Secure Agent: Review Security Report (PrefectHQ/fastmcp, 28k stars), Tenuo Agent Authorization (tenuo-ai/tenuo, 101 stars), OneCLI Gateway (nanocoai/nanoclaw, 31k stars) and Company Contact Finder (gooseworks-ai/goose-skills, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains Secure Agent?
mathematic-inc (a GitHub organization) maintains it in mathematic-inc/earl, which has 113 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 6, 2026.
Source: mathematic-inc/earl on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.