Agent skill

Agent-Core Security Checklist

by openJiuwen-ai in openJiuwen-ai/agent-core

A ten-category security checklist for the agent-core codebase, to run before any security-sensitive change or pull request: secrets, input validation, SQL, access control and prompt injection.

Apache-2.0Auto-check: notesSecurity

Install Agent-Core Security Checklist

skills CLI
$ npx skills add openJiuwen-ai/agent-core --skill security-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install openJiuwen-ai/agent-core security-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/openJiuwen-ai/agent-core.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/security-review .claude/skills/security-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-review
GitHub stars
446
Token cost
~1.7k tokens
SKILL.md length
538 words
Files
2
Skills in repo
10
Repo updated
First seen
Licence
Apache-2.0

At a glance

A ten-category security checklist for the agent-core codebase, to run before any security-sensitive change or pull request: secrets, input validation, SQL, access control and prompt injection.

  • Works in 10 steps: Secrets Management → Input Validation → SQL Injection → …
  • Reviewing a pull request that touches credentials, file paths, shell commands or SQL
  • SKILL.md covers 1. Secrets Management, 2. Input Validation, 3. SQL Injection and 4. Authentication and RBAC, plus 7 more sections
  • Needs API_KEY and OPENAI_API_KEY

What it does

This skill gives the agent a checklist of ten categories to run before a security-sensitive change or PR in the agent-core Python project. Each category states a rule and a set of checkboxes. Secrets management says credentials never enter source code, come from environment variables, keep .env files out of version control, and use mock defaults in tests. Input validation requires file paths to pass the project's safe_path helpers, rejects paths containing parent-directory segments, and builds shell commands through parameterized APIs.

SQL injection rules call for parameterized queries and allowlists for any dynamic table or column names. Authentication and RBAC rules require server-side enforcement, permission checks on every code path and resource limits. The prompt injection section keeps user strings out of system prompts without sanitization and separates user content from instructions in templates. The excerpt is cut off partway through that section, and a checklist.md file ships alongside.

When your agent uses it

  • Reviewing a pull request that touches credentials, file paths, shell commands or SQL
  • Checking agent capabilities for missing permission checks before merging
  • Auditing prompt templates for user content that could be injected into instructions

Example prompts

  • “Run the security checklist over the changes in this branch before I open the PR.”
  • “Check whether any file-path handling in the new tool skips safe_path validation.”
  • “Review our prompt templates for places where user text goes straight into the system prompt.”

Workflow steps

10 steps, taken from the step headings in SKILL.md.

  1. Secrets Management
  2. Input Validation
  3. SQL Injection
  4. Authentication and RBAC
  5. Prompt Injection
  6. CSRF / Request Validation
  7. Rate Limiting
  8. Sensitive Data in Logs
  9. Dependency Security
  10. Sandbox Isolation

What it can do on your machine

Read from SKILL.md and the folder at commit 9824919. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are python and bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • API_KEY
    • OPENAI_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Agent-Core Security Checklist loads about 1.7k tokens when it runs. Until then it costs about 30 tokens; SKILL.md has 538 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~30
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:21
    - [ ] `.env` files not committed (already in `.gitignore` — do not remove)
  • NoteMentions a .env fileSKILL.md:22
    `settings.json` deny rules block `Read(./.env)` and `Read(./**/secrets/**)`

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from openJiuwen-ai/agent-core at commit 9824919, republished under its Apache-2.0 licence (© openJiuwen-ai). 538 words, ~1,744 tokens.

Download SKILL.mdSave it as .claude/skills/security-review/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
security-review
description
10-category security checklist for agent-core: secrets, input validation, sandbox, and prompt injection.
disable-model-invocation
true

Security Review

Comprehensive security checklist for agent-core. Run through all 10 categories before any security-sensitive change or PR.

See .claude/rules/python/security.md for tool-specific guidance (bandit, pip-audit). See .claude/rules/security.md for credential, sandbox, and shell execution rules.

1. Secrets Management

Rule: Credentials never enter source code.

  • No API keys, tokens, or passwords hardcoded in .py files
  • All secrets loaded from environment variables via os.getenv()
  • .env files not committed (already in .gitignore — do not remove)
  • settings.json deny rules block Read(./.env) and Read(./**/secrets/**)
  • Test files use mock defaults: os.getenv("KEY", "mock-key-for-tests")
python
# Bad
API_KEY = "sk-1234567890abcdef"

# Good
import os
API_KEY = os.getenv("OPENAI_API_KEY")  # Must be set in environment

2. Input Validation

Rule: Validate all external input before use.

  • User-supplied file paths checked with safe_path utilities
  • Paths rejected if they contain .. or resolve outside allowed scope
  • Shell commands constructed via parameterized APIs, not string concatenation
  • URL parameters and query strings sanitized before use

For sys_operation:

python
from openjiuwen.core.common.security import safe_path

def execute_command(user_path: str, working_dir: Path) -> None:
    validated = safe_path(user_path, allowed_base=working_dir)
    if validated is None:
        raise SecurityError(f"Path outside allowed scope: {user_path}")
    # Proceed with validated path

3. SQL Injection

Rule: Use parameterized queries for all database operations.

  • No string interpolation in SQL: f"SELECT * FROM {table}" is forbidden
  • All SQL uses parameterized placeholders: "WHERE id = ?", (id,)
  • Table/column names validated against an allowlist if dynamic
python
# Bad
cursor.execute(f"SELECT * FROM {table_name} WHERE id = {user_id}")

# Good
cursor.execute(
    "SELECT * FROM sessions WHERE id = ?",
    (session_id,)
)

4. Authentication and RBAC

Rule: Access control must be enforced server-side, not just client-side.

  • All agent capabilities gated behind permission checks in core/security/
  • Guardrails in openjiuwen/core/security/ verify permissions before execution
  • No capability bypassed by missing checks on alternate code paths
  • Resource limits enforced (rate limiting, concurrent request limits)

5. Prompt Injection

Rule: openjiuwen/harness/prompts/ must guard against injected user content.

  • User-provided strings never concatenated directly into system prompts without sanitization
  • Prompt templates use placeholder isolation (separate user content from instruction)
  • Rail outputs validated before being passed to downstream components
  • The security rail (openjiuwen/harness/rails/) correctly blocks dangerous patterns

Prompt injection is agent-core's most unique security concern. Attackers may try to inject instructions into conversation history to manipulate agent behavior:

python
# Bad — user content injected into system prompt
system_prompt = f"You are a helpful assistant. User said: {user_message}"

# Good — user content kept in separate context slot
system_prompt = SYSTEM_INSTRUCTIONS
context = {
    "user_message": sanitize_for_display(user_message),
    "conversation_history": conversation,
}

6. CSRF / Request Validation

Rule: All mutating requests include validation.

  • core/session/ validates that requests originate from legitimate sessions
  • Session IDs are non-guessable (use secrets.token_urlsafe())
  • Session state changes are idempotent or protected by transaction semantics
  • No state-modifying operations accessible without session context
Show full SKILL.md (212 more words)Show less

7. Rate Limiting

Rule: Protect core/runner/ and core/runner/ resources from exhaustion.

  • Runner.resource_mgr enforces limits on concurrent agent executions
  • Memory usage bounded for long-running sessions
  • Compaction triggers prevent unbounded context growth
  • Tool call frequency limits enforced per session

8. Sensitive Data in Logs

Rule: Logs must not expose credentials, tokens, or sensitive data.

  • No API keys, tokens, or passwords in log output
  • Use structured logging with explicit field names, not f-string interpolation
  • Error messages do not include sensitive user data
  • openjiuwen.core.common.logging used instead of print()
python
# Bad
logger.info(f"Authenticated user {user_id} with token {token}")

# Good
logger.info("User authenticated", extra={"user_id": user_id})

9. Dependency Security

Rule: All dependencies scanned before merging PRs.

  • New dependencies reviewed for known CVEs: pip-audit
  • New network-facing dependencies reviewed for security implications
  • bandit -r openjiuwen/ -ll passes (no HIGH/CRITICAL findings)
  • Third-party code in core/sys_operation/ and core/security/ minimized
bash
# Run before merging dependency changes
pip-audit
bandit -r openjiuwen/ -ll

10. Sandbox Isolation

Rule: core/sys_operation/sandbox/ must provide genuine isolation.

  • File operations respect path scoping (no escape via ../)
  • Shell execution runs in a restricted environment
  • Network access is explicitly allowed/denied, not default-open
  • Cleanup runs after every operation, even on failure
  • Interrupt/confirm flows preserved for user-facing operations

For sandbox implementations, verify:

python
# Path isolation
def sandbox_read(path: Path, allowed_base: Path) -> str:
    resolved = (allowed_base / path).resolve()
    if not resolved.is_relative_to(allowed_base):
        raise SecurityError(f"Escape attempt: {path}")
    return resolved.read_text()

Pre-Review Checklist

Before marking a security-sensitive PR as ready for review, run through all 10 categories above. Document the review in the PR description:

Security Review
===============
Secrets:        PASS (no hardcoded credentials)
Input Val:      PASS (safe_path used for all user paths)
SQL Injection:  PASS (parameterized queries only)
Auth/RBAC:      PASS (guardrails enforce permissions)
Prompt Inject:  PASS (user content isolated from system prompts)
CSRF:           PASS (session IDs are non-guessable)
Rate Limiting:  PASS (resource_mgr enforces limits)
Log Safety:     PASS (no credentials in structured logs)
Dependencies:   PASS (bandit + pip-audit clean)
Sandbox:        PASS (path scoping verified)

For changes to core/security/, core/sys_operation/, or openjiuwen/extensions/sys_operation/sandbox/, request a dedicated security review from a second reviewer.

© openJiuwen-ai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .claude/skills/security-review of openJiuwen-ai/agent-core.

  • SKILL.md
  • checklist.md

Open the folder on GitHubat commit 9824919

Compare with similar skills

Agent-Core Security Checklist next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Agent-Core Security Checklist compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Agent-Core Security Checklist this skillopenJiuwen-ai/agent-core446—~1.7kAutomated safety check: NotesApache-2.0
Security AuditTheDecipherist/claude-code-mastery551—~1.3kAutomated safety check: NotesMIT
CodeQL Security Scantrailofbits/skills7.5k—~4.6kAutomated safety check: NotesCC-BY-SA-4.0
Security Review ChecklistZeroDeng01/sublinkPro1.7k—~2.3kAutomated safety check: PassMIT
Python kwargs setattr Allowlistmicrosoft/onnxruntime22k—~737Automated safety check: PassMIT
Codewhale Security Reviewcodewhale-hq/Codewhale41k—~844Automated safety check: PassMIT

Similar skills

  • Security Audit

    TheDecipherist/claude-code-mastery

    Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

    551 GitHub stars~1.3k tokensUpdated 5 mo ago
    SecurityAuto-check: notes
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.5k GitHub stars~4.6k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Security Review Checklist

    ZeroDeng01/sublinkPro

    Checklist-driven security review for changes to authentication, authorization, MFA, secrets, input validation and other security-critical code.

    1.7k GitHub stars~2.3k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Python kwargs setattr Allowlist

    microsoft/onnxruntime

    Official

    Shows how to replace unsafe hasattr and setattr loops over user-controlled kwargs with an explicit allowlist when configuring ONNX Runtime option objects.

    22k GitHub stars~737 tokensUpdated today
    SecurityAuto-check passed
  • Codewhale Security Review

    codewhale-hq/Codewhale

    Reviews a diff, module or network surface for exploitable defects, mapping trust boundaries and sinks, then reports only findings with a verified reachable path and a fix.

    41k GitHub stars~844 tokensUpdated today
    SecurityAuto-check passed
  • Security Audit

    jellydn/my-ai-tools

    A skill your agent uses when reviewing code for security vulnerabilities, hardening an application, or deriving security requirements from OWASP/ASVS guidance.

    123 GitHub stars~2.9k tokensUpdated yesterday
    SecurityAuto-check: notes

More from openJiuwen-ai/agent-core

All 10 skills in this repo
  • Skill Safety Evaluator

    openJiuwen-ai/agent-core

    Static safety audit of a SKILL.md that scores five dimensions and acts as a gate: skills below the pass line do not ship, whatever else they score.

    446 GitHub stars~3.5k tokensUpdated today
    Auto-check: warnings
  • Repository Health and Gap Assessor

    openJiuwen-ai/agent-core

    Runs a read-only assessment in one of two modes, a repository health check or a runtime extension gap review, and reports findings as a markdown table.

    446 GitHub stars~613 tokensUpdated today
    Auto-check passed
  • Engineering Communication Rules

    openJiuwen-ai/agent-core

    Chinese-language rules for how an agent writes commit messages, PR descriptions, session journals, handoff issues and requests for help.

    446 GitHub stars~625 tokensUpdated today
    Auto-check passed
  • Python Patterns for agent-core

    openJiuwen-ai/agent-core

    Reference for idiomatic Python in the agent-core codebase: immutability, protocols, exception hierarchies, context managers and async patterns.

    446 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Agent-Core Python Testing

    openJiuwen-ai/agent-core

    Pytest patterns for the agent-core codebase: a red-green-refactor workflow, conftest fixtures, custom marks, monkeypatch and patch mocking, and async tests.

    446 GitHub stars~2.3k tokensUpdated today
    Auto-check passed
  • Verification Loop

    openJiuwen-ai/agent-core

    Formalizes agent-core's make check/type-check/test/fix pipeline into a structured 6-phase verification skill.

    446 GitHub stars~818 tokensUpdated today
    Auto-check passed

Works with

Questions about Agent-Core Security Checklist

What does Agent-Core Security Checklist do?

A ten-category security checklist for the agent-core codebase, to run before any security-sensitive change or pull request: secrets, input validation, SQL, access control and prompt injection. This skill gives the agent a checklist of ten categories to run before a security-sensitive change or PR in the agent-core Python project. Each category states a rule and a set of checkboxes.

When should I use Agent-Core Security Checklist?

Agent-Core Security Checklist fits situations like: reviewing a pull request that touches credentials, file paths, shell commands or SQL; checking agent capabilities for missing permission checks before merging; auditing prompt templates for user content that could be injected into instructions.

How do I install Agent-Core Security Checklist in Claude Code?

Run `npx skills add openJiuwen-ai/agent-core --skill security-review -a claude-code`. Or copy the skill folder (.claude/skills/security-review in openJiuwen-ai/agent-core) into .claude/skills/security-review in your project. Claude Code loads it when a task matches its description.

How do I install Agent-Core Security Checklist in Codex?

Run `npx skills add openJiuwen-ai/agent-core --skill security-review -a codex`. Or copy the skill folder (.claude/skills/security-review in openJiuwen-ai/agent-core) into .agents/skills/security-review in your project. Codex loads it when a task matches its description.

Can I use Agent-Core Security Checklist in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openJiuwen-ai/agent-core --skill security-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-review, .gemini/skills/security-review, .github/skills/security-review and .opencode/skills/security-review in your project.

What does Agent-Core Security Checklist need to run?

Going by SKILL.md and its folder, Agent-Core Security Checklist needs credentials named API_KEY and OPENAI_API_KEY.

Does Agent-Core Security Checklist access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Agent-Core Security Checklist safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Agent-Core Security Checklist use?

Agent-Core Security Checklist is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Agent-Core Security Checklist use?

About 1.7k tokens (SKILL.md is roughly 7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Agent-Core Security Checklist?

Skills that share tags, products or a category with Agent-Core Security Checklist: Security Audit (TheDecipherist/claude-code-mastery, 551 stars), CodeQL Security Scan (trailofbits/skills, 7.5k stars), Security Review Checklist (ZeroDeng01/sublinkPro, 1.7k stars) and Python kwargs setattr Allowlist (microsoft/onnxruntime, 22k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Agent-Core Security Checklist?

openJiuwen-ai (a GitHub organization) maintains it in openJiuwen-ai/agent-core, which has 446 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on October 11, 2026.

Source: openJiuwen-ai/agent-core on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.