Iron Proxy Gateway for NanoClaw
nanocoai/nanoclaw
Installs or refreshes Iron Proxy and its Iron Control web console for NanoClaw, with a local Docker setup, database, credentials and a human approval bridge.
服务端路径安全与文件访问编码规范。在编写文件下载路由、Agent 工具(文件读取/目录列出)、数据连接器/Loader、Workspace 路径操作、沙箱配置时使用。
$ npx skills add microsoft/data-formulator --skill path-safety -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install microsoft/data-formulator path-safety --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/microsoft/data-formulator.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.cursor/skills/path-safety .claude/skills/path-safety && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "path-safety" agent skill from https://github.com/microsoft/data-formulator/tree/main/.cursor/skills/path-safety into .claude/skills/path-safety/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "path-safety", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/microsoft/data-formulator/tree/main/.cursor/skills/path-safetyType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add microsoft/data-formulator --skill path-safety -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install microsoft/data-formulator path-safety --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/microsoft/data-formulator.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.cursor/skills/path-safety .agents/skills/path-safety && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "path-safety" agent skill from https://github.com/microsoft/data-formulator/tree/main/.cursor/skills/path-safety into .agents/skills/path-safety/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "path-safety", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add microsoft/data-formulator --skill path-safety -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install microsoft/data-formulator path-safety --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/microsoft/data-formulator.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.cursor/skills/path-safety .cursor/skills/path-safety && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "path-safety" agent skill from https://github.com/microsoft/data-formulator/tree/main/.cursor/skills/path-safety into .cursor/skills/path-safety/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "path-safety", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/microsoft/data-formulator.git --path .cursor/skills/path-safety--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add microsoft/data-formulator --skill path-safety -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install microsoft/data-formulator path-safety --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/microsoft/data-formulator.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.cursor/skills/path-safety .gemini/skills/path-safety && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "path-safety" agent skill from https://github.com/microsoft/data-formulator/tree/main/.cursor/skills/path-safety into .gemini/skills/path-safety/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "path-safety", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install microsoft/data-formulator path-safetyInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add microsoft/data-formulator --skill path-safety -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/microsoft/data-formulator.git skills-src && mkdir -p .github/skills && cp -r skills-src/.cursor/skills/path-safety .github/skills/path-safety && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "path-safety" agent skill from https://github.com/microsoft/data-formulator/tree/main/.cursor/skills/path-safety into .github/skills/path-safety/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "path-safety", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add microsoft/data-formulator --skill path-safety -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install microsoft/data-formulator path-safety --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/microsoft/data-formulator.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.cursor/skills/path-safety .opencode/skills/path-safety && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "path-safety" agent skill from https://github.com/microsoft/data-formulator/tree/main/.cursor/skills/path-safety into .opencode/skills/path-safety/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "path-safety", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
path-safety服务端路径安全与文件访问编码规范。在编写文件下载路由、Agent 工具(文件读取/目录列出)、数据连接器/Loader、Workspace 路径操作、沙箱配置时使用。
Path Safety is an agent skill from microsoft/data-formulator, published by the product's own GitHub organization. 服务端路径安全与文件访问编码规范。在编写文件下载路由、Agent 工具(文件读取/目录列出)、数据连接器/Loader、Workspace 路径操作、沙箱配置时使用。
Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud. It works with Docker. The repository describes itself as: 🪄 Data Formulator is an interactive AI-powered data analysis system makes it easy to connect, explore and visualize data. The licence is MIT.
2 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 5477f0e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are python).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Path Safety loads about 1.2k tokens when it runs. Until then it costs about 24 tokens; SKILL.md has 159 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from microsoft/data-formulator at commit 5477f0e, republished under its MIT licence (© microsoft). 159 words, ~1,165 tokens.
.claude/skills/path-safety/SKILL.md (or your agent's skills folder).来源:
docs/dev-guides/8-path-safety.md(正式开发规范)+design-docs/issues/002-arbitrary-file-read-audit.md(安全审计复核)。 本文档提炼了 6 条必须遵守的编码规范。违反任一条即可能引入路径穿越(LFI)漏洞。
ConfinedDir.resolve() + send_file,禁用 send_from_directory原因:send_from_directory(dir, user_input) 内部会对 user_input 二次解析路径,与前置安全检查形成 TOCTOU 不一致。
# ❌ BAD — 安全检查用 resolved target,发送用原始 filename,两次解析不一致
target = (scratch_dir / filename).resolve()
target.relative_to(scratch_dir.resolve()) # 检查通过
return send_from_directory(str(scratch_dir), filename) # 再次解析
# ✅ GOOD — 检查和发送用同一个 resolved path
scratch_jail = workspace.confined_scratch
target = scratch_jail.resolve(filename)
return send_file(target) # 直接用已验证的路径send_file(Path) 会根据扩展名自动推断 MIME type,无需额外处理。
ConfinedDir,禁止 str.startswith原因:str(path).startswith(str(root)) 存在前缀碰撞缺陷(如 /workspace vs /workspace_evil)。
# ❌ BAD
if not str(resolved).startswith(str(root_resolved) + os.sep):
raise ValueError("escape")
# ✅ GOOD — 统一走 ConfinedDir,内部使用 Path.is_relative_to()
jail = ConfinedDir(root_resolved, mkdir=False)
target = jail.resolve(user_input)Workspace.confined_*原因:Agent 工具参数由 LLM 生成,必须视为间接用户输入。不要在工具内手写 Path(root) / rel_path 或 resolve() + relative_to();入口处复用 Workspace 暴露的 ConfinedDir。
# ❌ BAD — 手写路径拼接和校验
def _tool_read_file(self, args, workspace_path):
target = (workspace_path / rel_path).resolve()
target.relative_to(workspace_path)
# ✅ GOOD — 入口拿到 ConfinedDir,工具只调用 jail.resolve()
def _execute_tool(self, name, args):
workspace_jail = self.workspace.confined_root
scratch_jail = self.workspace.confined_scratch
return self._tool_read_file(args, workspace_jail)
def _tool_read_file(self, args, workspace_jail):
target = workspace_jail.resolve(args.get("path", ""))ConfinedDir,禁止裸路径拼接原因:Path(root) / user_input 是路径穿越的高频入口。ConfinedDir 封装了三层防御(拒绝绝对路径 → 拒绝 .. 段 → resolve + is_relative_to)。
from data_formulator.security.path_safety import ConfinedDir
# ❌ BAD — 手动拼接 + 手动校验,容易遗漏
local_file = tmp_path / blob_relative_name
local_file.parent.mkdir(parents=True, exist_ok=True)
local_file.write_bytes(data)
# ✅ GOOD — ConfinedDir 自动校验 + 创建父目录
jail = ConfinedDir(tmp_path, mkdir=False)
jail.write(blob_relative_name, data) # 自动校验 + 写入用户输入(filename / relative_path / blob key)
│
▼
safe_data_filename() / secure_filename() ← 第一层:输入清洗
│
▼
ConfinedDir.resolve() ← 第二层:路径约束
│
▼
安全的 Path 对象使用 Workspace.get_file_path() 的场景不需要手动调用 ConfinedDir,因为它内部已包含等价的校验。
原因:桌面单用户模式允许访问本机文件系统(预期行为),但多用户/云部署下等于开放服务器读权限。
规范:任何新的 Loader / Connector 如果涉及直接读取宿主文件系统(不通过 Workspace API),必须:
data_loader/__init__.py 的 _enforce_deployment_restrictions() 中注册禁用规则create_connector() 会拒绝已禁用的类型# data_loader/__init__.py — 参考 local_folder 的处理方式
def _enforce_deployment_restrictions():
backend = os.environ.get("WORKSPACE_BACKEND", "local")
if backend != "local":
for key in ("local_folder", "your_new_local_loader"):
if key in DATA_LOADERS:
del DATA_LOADERS[key]
DISABLED_LOADERS[key] = f"{key} disabled in multi-user mode"判断标准:如果 Loader 的构造函数接受一个用户可控的本机路径(如 root_dir),它就需要部署守卫。
原因:not_a_sandbox 模式下 LLM 生成的代码在宿主进程直接执行,可绕过所有路径检查。
app.py 已在启动时检测此配置并输出 logger.critical 警告。新增的沙箱模式或部署脚本应确保:
WORKSPACE_BACKEND != "local" 时,SANDBOX 必须为 docker 或 localSANDBOX=docker| 场景 | 必须做的事 |
|---|---|
| 新增文件下载路由 | 用 ConfinedDir.resolve() 得到路径,再 send_file(resolved_path);不用 send_from_directory |
| 新增 Agent 工具(读文件/列目录) | 入口复用 workspace.confined_root / workspace.confined_scratch,工具内只调用 jail.resolve() |
| 路径包含判断 | 用 ConfinedDir.resolve(),不要手写 Path.is_relative_to() 或 str.startswith() |
Path(root) / variable 模式 | 改用 ConfinedDir 或 Workspace.get_file_path() |
| 新增本机文件系统 Loader | 在 _enforce_deployment_restrictions() 中注册多用户禁用 |
| 部署配置 | 多用户模式必须 SANDBOX=docker 或 SANDBOX=local |
docs/dev-guides/8-path-safety.md — 服务端路径安全开发规范design-docs/6-path-safety-confined-dir.md — 剩余未完成实现项状态页design-docs/issues/002-arbitrary-file-read-audit.md — 安全审计复核报告py-src/data_formulator/security/path_safety.py — ConfinedDir 源码© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .cursor/skills/path-safety of microsoft/data-formulator.
Open the folder on GitHubat commit 5477f0e
Path Safety next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Path Safety this skillmicrosoft/data-formulator | 18k | — | ~1.2k | Automated safety check: Pass | MIT | |
| Iron Proxy Gateway for NanoClawnanocoai/nanoclaw | 31k | — | ~4.6k | Automated safety check: Notes | MIT | |
| GreptimeDB Dev Docker ImageGreptimeTeam/greptimedb | 6.7k | — | ~4k | Automated safety check: Notes | Apache-2.0 | |
| Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit | 260 | 6 repos | ~1.1k | Automated safety check: Notes | Custom licence | |
| LangBot Deployment Guidelangbot-app/LangBot | 18k | — | ~1.2k | Automated safety check: Notes | Apache-2.0 | |
| Build Openshell Mxc WindowsNVIDIA/OpenShell | 15k | — | ~4.9k | Automated safety check: Pass | Apache-2.0 |
nanocoai/nanoclaw
Installs or refreshes Iron Proxy and its Iron Control web console for NanoClaw, with a local Docker setup, database, credentials and a human approval bridge.
GreptimeTeam/greptimedb
Packages a locally built GreptimeDB debug binary into a development-only Docker image for local-cluster testing, with an optional push to a dev registry.
maslennikov-ig/claude-code-orchestrator-kit
Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…
langbot-app/LangBot
Deploys and configures a LangBot instance with Docker Compose or Kubernetes, covering config.yaml, the Box sandbox runtime, the plugin runtime and the global API key.
NVIDIA/OpenShell
Maintain and validate OpenShell's build-only Windows MSVC lane for x64 and ARM64.
yansongda/pay
A skill your agent uses when local PHP environment is unavailable.
microsoft/data-formulator
统一错误处理系统。在添加 API 端点、修改错误处理、添加前端 API 调用、编写错误相关测试时使用. An agent skill from microsoft/data-formulator.
microsoft/data-formulator
LLM Agent 多语言注入规范。在修改 Agent 提示词、添加新的 Agent 端点、处理用户可见的后端消息(messagecode)时使用。
microsoft/data-formulator
Discover connected data sources, add new data connectors through a user-confirmed form, inspect table metadata, and run bounded read-only probes when the current workspace data is insufficient.
microsoft/data-formulator
Turn an exploration (threads, findings, charts) into a single Markdown report — note, blog post, executive summary, KPI dashboard, slide brief, or multi-section analytical report, with embedded…
microsoft/data-formulator
The analyst's built-in capabilities: data-inspection tools and the always-available actions (visualize and askuser).
Works with
Categories
服务端路径安全与文件访问编码规范。在编写文件下载路由、Agent 工具(文件读取/目录列出)、数据连接器/Loader、Workspace 路径操作、沙箱配置时使用。. Path Safety is an agent skill from microsoft/data-formulator, published by the product's own GitHub organization.
Path Safety fits situations like: devOps & Cloud work in your project.
Run `npx skills add microsoft/data-formulator --skill path-safety -a claude-code`. Or copy the skill folder (.cursor/skills/path-safety in microsoft/data-formulator) into .claude/skills/path-safety in your project. Claude Code loads it when a task matches its description.
Run `npx skills add microsoft/data-formulator --skill path-safety -a codex`. Or copy the skill folder (.cursor/skills/path-safety in microsoft/data-formulator) into .agents/skills/path-safety in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/data-formulator --skill path-safety -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/path-safety, .gemini/skills/path-safety, .github/skills/path-safety and .opencode/skills/path-safety in your project.
SKILL.md names no scripts, command-line tools or credentials: Path Safety is instructions for the agent only. Our summary lists: Python 3; Docker.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Path Safety is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.2k tokens (SKILL.md is roughly 4.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Path Safety: Iron Proxy Gateway for NanoClaw (nanocoai/nanoclaw, 31k stars), GreptimeDB Dev Docker Image (GreptimeTeam/greptimedb, 6.7k stars), Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars) and LangBot Deployment Guide (langbot-app/LangBot, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
microsoft (a GitHub organization, an official publisher) maintains it in microsoft/data-formulator, which has 17,540 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 8, 2026.
Source: microsoft/data-formulator on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.