Skill Scanner
getsentry/skills
Scan agent skills for security issues. An agent skill from getsentry/skills.
AI Agent 安全开发与防护最佳实践,包含prompt注入防护、代码执行安全、敏感信息保护、合规审计全流程规范. An agent skill from ProgrammerAnthony/Expert-Coding-Harness.
$ npx skills add ProgrammerAnthony/Expert-Coding-Harness --skill ai-agent-security -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ProgrammerAnthony/Expert-Coding-Harness ai-agent-security --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ProgrammerAnthony/Expert-Coding-Harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/ai-agent-security .claude/skills/ai-agent-security && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "ai-agent-security" agent skill from https://github.com/ProgrammerAnthony/Expert-Coding-Harness/tree/master/skills/ai-agent-security into .claude/skills/ai-agent-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ai-agent-security", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ProgrammerAnthony/Expert-Coding-Harness/tree/master/skills/ai-agent-securityType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ProgrammerAnthony/Expert-Coding-Harness --skill ai-agent-security -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ProgrammerAnthony/Expert-Coding-Harness ai-agent-security --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ProgrammerAnthony/Expert-Coding-Harness.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/ai-agent-security .agents/skills/ai-agent-security && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "ai-agent-security" agent skill from https://github.com/ProgrammerAnthony/Expert-Coding-Harness/tree/master/skills/ai-agent-security into .agents/skills/ai-agent-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ai-agent-security", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ProgrammerAnthony/Expert-Coding-Harness --skill ai-agent-security -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ProgrammerAnthony/Expert-Coding-Harness ai-agent-security --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ProgrammerAnthony/Expert-Coding-Harness.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/ai-agent-security .cursor/skills/ai-agent-security && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "ai-agent-security" agent skill from https://github.com/ProgrammerAnthony/Expert-Coding-Harness/tree/master/skills/ai-agent-security into .cursor/skills/ai-agent-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ai-agent-security", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ProgrammerAnthony/Expert-Coding-Harness.git --path skills/ai-agent-security--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ProgrammerAnthony/Expert-Coding-Harness --skill ai-agent-security -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ProgrammerAnthony/Expert-Coding-Harness ai-agent-security --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ProgrammerAnthony/Expert-Coding-Harness.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/ai-agent-security .gemini/skills/ai-agent-security && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "ai-agent-security" agent skill from https://github.com/ProgrammerAnthony/Expert-Coding-Harness/tree/master/skills/ai-agent-security into .gemini/skills/ai-agent-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ai-agent-security", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ProgrammerAnthony/Expert-Coding-Harness ai-agent-securityInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ProgrammerAnthony/Expert-Coding-Harness --skill ai-agent-security -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ProgrammerAnthony/Expert-Coding-Harness.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/ai-agent-security .github/skills/ai-agent-security && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "ai-agent-security" agent skill from https://github.com/ProgrammerAnthony/Expert-Coding-Harness/tree/master/skills/ai-agent-security into .github/skills/ai-agent-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ai-agent-security", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ProgrammerAnthony/Expert-Coding-Harness --skill ai-agent-security -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ProgrammerAnthony/Expert-Coding-Harness ai-agent-security --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ProgrammerAnthony/Expert-Coding-Harness.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/ai-agent-security .opencode/skills/ai-agent-security && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "ai-agent-security" agent skill from https://github.com/ProgrammerAnthony/Expert-Coding-Harness/tree/master/skills/ai-agent-security into .opencode/skills/ai-agent-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ai-agent-security", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
ai-agent-securityAI Agent 安全开发与防护最佳实践,包含prompt注入防护、代码执行安全、敏感信息保护、合规审计全流程规范. An agent skill from ProgrammerAnthony/Expert-Coding-Harness.
AI Agent Security is an agent skill from ProgrammerAnthony/Expert-Coding-Harness. AI Agent 安全开发与防护最佳实践,包含prompt注入防护、代码执行安全、敏感信息保护、合规审计全流程规范。
Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Prompt injection and agent security. The repository describes itself as: 生产级 AI Agent 技能集,辅助AI Harness应用于企业开发,覆盖代码审查、代码安全审计、TDD、需求工程、实施计划与子代理编排、架构设计、调试、前端开发与技能创建全流程。 The licence is MIT.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit ab0b827. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are python).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
AI Agent Security loads about 3k tokens when it runs. Until then it costs about 19 tokens; SKILL.md has 81 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from ProgrammerAnthony/Expert-Coding-Harness at commit ab0b827, republished under its MIT licence (© ProgrammerAnthony). 81 words, ~2,984 tokens.
.claude/skills/ai-agent-security/SKILL.md (or your agent's skills folder).本技能基于生产级AI Agent防护方案整理,覆盖AI系统全生命周期的安全风险防控,符合等保2.0三级要求与数据安全法规定。
| 风险类型 | 危害等级 | 典型场景 |
|---|---|---|
| Prompt注入攻击 | 高危 | 诱导Agent执行恶意指令、绕过安全限制 |
| 敏感信息泄露 | 高危 | Agent输出内部数据、密钥、用户隐私 |
| 恶意代码执行 | 极高危 | Agent生成并执行恶意代码,控制服务器 |
| 数据投毒 | 中危 | 污染训练数据/知识库,导致Agent输出错误信息 |
| 越权访问 | 高危 | Agent绕过权限控制,访问未授权资源 |
| 合规风险 | 中危 | 违反数据安全法、个人信息保护法等法规 |
from typing import List
import re
class PromptInjectionDetector:
def __init__(self):
self.risk_patterns = [
# 指令绕过模式
r"(ignore|disregard|forget).*(previous|above|prior).*(instructions|prompt|rules)",
r"(you are|act as|pretend to be).*(not|no longer).*(assistant|AI|bot)",
r"(override|bypass|disable).*(security|safety|content).*(filters|policies|restrictions)",
# 系统指令模式
r"```system\s*",
r"<\|system\|>",
r"SYSTEM:",
# 诱导输出模式
r"(output|print|reveal|disclose).*(prompt|instructions|rules|system)",
r"(show|tell|list).*(all|full|entire).*(prompt|context|memory)"
]
self.suspicious_keywords = ["jailbreak", "DAN", "dev mode", "developer mode", "unrestricted"]
def detect(self, prompt: str, threshold: float = 0.7) -> dict:
risk_score = 0.0
matched_patterns = []
# 正则匹配检测
for pattern in self.risk_patterns:
if re.search(pattern, prompt, re.IGNORECASE):
risk_score += 0.2
matched_patterns.append(pattern)
# 关键词检测
for keyword in self.suspicious_keywords:
if keyword.lower() in prompt.lower():
risk_score += 0.15
# 特殊字符检测
special_char_ratio = len(re.findall(r'[^\w\s,.,。?!;:""''()()、]', prompt)) / len(prompt) if prompt else 0
if special_char_ratio > 0.3:
risk_score += 0.25
return {
"is_risk": risk_score >= threshold,
"risk_score": risk_score,
"matched_patterns": matched_patterns
}
# 使用示例
detector = PromptInjectionDetector()
result = detector.detect(user_input)
if result["is_risk"]:
raise SecurityError("疑似Prompt注入攻击,请求已拦截")def normalize_input(prompt: str) -> str:
# 移除特殊标记
prompt = re.sub(r'<\|.*?\|>', '', prompt)
# 移除系统指令关键词
prompt = re.sub(r'(?i)\b(system|assistant|user):\s*', '', prompt)
# 移除代码块标记
prompt = re.sub(r'```[\s\S]*?```', '[CODE_BLOCK_REMOVED]', prompt)
# 截断过长输入
if len(prompt) > 4000:
prompt = prompt[:4000] + "[TRUNCATED]"
return promptimport re
from typing import List
class OutputValidator:
def __init__(self):
self.sensitive_patterns = [
# 密钥模式
r'(sk_|api_key|secret|token|password)\s*[:=]\s*[\w-]+',
# 隐私数据模式
r'\b\d{11}\b', # 手机号
r'\b\d{18}\b', # 身份证号
r'\b[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\.[A-Z|a-z]{2,}\b', # 邮箱
# 内部信息模式
r'(内部|机密|绝密|保密|敏感)',
r'(内网|192\.168\.|10\.|172\.1[6-9]\.|172\.2[0-9]\.|172\.3[0-1]\.)'
]
def validate(self, output: str) -> dict:
risks = []
cleaned_output = output
# 敏感信息检测与脱敏
for pattern in self.sensitive_patterns:
matches = re.findall(pattern, output, re.IGNORECASE)
if matches:
risks.append(f"检测到敏感信息: {pattern}")
# 脱敏处理
cleaned_output = re.sub(pattern, '***', cleaned_output, flags=re.IGNORECASE)
# 恶意代码检测
malicious_code_patterns = [
r'(rm\s+-rf|format\s+/|del\s+/f/s/q|reg\s+delete)',
r'(curl|wget).*http.*\|.*sh',
r'(eval|exec|system|popen|subprocess\.call)',
r'(base64.*\|.*bash|bash.*<\(curl)'
]
for pattern in malicious_code_patterns:
if re.search(pattern, output, re.IGNORECASE):
risks.append(f"检测到恶意代码: {pattern}")
cleaned_output = "输出包含恶意代码,已拦截"
break
return {
"is_risk": len(risks) > 0,
"risks": risks,
"cleaned_output": cleaned_output
}def verify_facts(output: str, knowledge_base: List[str]) -> dict:
"""基于知识库验证输出事实正确性"""
import spacy
nlp = spacy.load("zh_core_web_sm")
doc = nlp(output)
facts = [ent.text for ent in doc.ents if ent.label_ in ["PERSON", "ORG", "DATE", "EVENT"]]
unverified_facts = []
for fact in facts:
if not any(fact in kb_entry for kb_entry in knowledge_base):
unverified_facts.append(fact)
return {
"has_hallucination": len(unverified_facts) > 0,
"unverified_facts": unverified_facts,
"confidence": 1.0 - (len(unverified_facts) / max(len(facts), 1))
}import subprocess
import tempfile
import os
from pathlib import Path
class CodeSandbox:
def __init__(self, memory_limit: str = "256m", cpu_limit: float = 0.5, timeout: int = 10):
self.memory_limit = memory_limit
self.cpu_limit = cpu_limit
self.timeout = timeout
def execute(self, code: str, language: str = "python") -> dict:
# 创建临时目录
with tempfile.TemporaryDirectory() as tmpdir:
tmpdir = Path(tmpdir)
# 写入代码文件
code_file = tmpdir / "code"
code_file.write_text(code)
try:
if language == "python":
cmd = [
"docker", "run", "--rm",
"--memory", self.memory_limit,
"--cpus", str(self.cpu_limit),
"--network", "none", # 禁用网络
"--read-only", # 只读文件系统
"-v", f"{tmpdir}:/app",
"python:3.11-slim",
"python", "/app/code"
]
elif language == "javascript":
cmd = [
"docker", "run", "--rm",
"--memory", self.memory_limit,
"--cpus", str(self.cpu_limit),
"--network", "none",
"--read-only",
"-v", f"{tmpdir}:/app",
"node:20-slim",
"node", "/app/code"
]
else:
return {"error": "不支持的语言"}
# 执行代码
result = subprocess.run(
cmd,
capture_output=True,
text=True,
timeout=self.timeout
)
return {
"success": result.returncode == 0,
"stdout": result.stdout,
"stderr": result.stderr,
"returncode": result.returncode
}
except subprocess.TimeoutExpired:
return {"error": "执行超时"}
except Exception as e:
return {"error": f"执行错误: {str(e)}"}from typing import Dict, List, Callable
class ToolAuthorization:
def __init__(self):
# 角色-权限映射
self.role_permissions: Dict[str, List[str]] = {
"admin": ["*"],
"developer": ["code_execute", "git_*", "database_query"],
"user": ["web_search", "file_read", "calculator"]
}
# 工具风险等级
self.tool_risk: Dict[str, str] = {
"code_execute": "high",
"database_write": "high",
"file_delete": "high",
"email_send": "medium",
"web_search": "low",
"calculator": "low"
}
def check_permission(self, user_role: str, tool_name: str) -> bool:
permissions = self.role_permissions.get(user_role, [])
# 通配符匹配
for perm in permissions:
if perm == "*":
return True
if perm.endswith("*") and tool_name.startswith(perm[:-1]):
return True
if perm == tool_name:
return True
return False
def require_mfa(self, tool_name: str) -> bool:
"""高风险工具需要二次验证"""
return self.tool_risk.get(tool_name, "low") == "high"import json
from datetime import datetime
from typing import Any
class AuditLogger:
def __init__(self, log_path: str = "audit.log"):
self.log_path = log_path
def log_event(self,
event_type: str,
user_id: str,
session_id: str,
tool_name: str = None,
input_data: Any = None,
output_data: Any = None,
is_risk: bool = False,
risk_details: List[str] = None):
event = {
"timestamp": datetime.utcnow().isoformat(),
"event_type": event_type,
"user_id": user_id,
"session_id": session_id,
"tool_name": tool_name,
"input_hash": hash(str(input_data)) if input_data else None,
"output_hash": hash(str(output_data)) if output_data else None,
"is_risk": is_risk,
"risk_details": risk_details or []
}
with open(self.log_path, "a", encoding="utf-8") as f:
f.write(json.dumps(event, ensure_ascii=False) + "\n")
# 使用示例
audit_logger = AuditLogger()
audit_logger.log_event(
event_type="tool_call",
user_id="user123",
session_id="session456",
tool_name="code_execute",
input_data=user_code,
output_data=execution_result,
is_risk=False
)class DataCompliance:
def __init__(self):
self.sensitive_data_types = ["个人信息", "隐私数据", "商业秘密", "重要数据"]
def data_processing_approval(self, data_type: str, processing_purpose: str) -> bool:
"""数据处理审批流程"""
if data_type in self.sensitive_data_types:
# 需要审批流程
return self.check_approval_flow(data_type, processing_purpose)
return True
def data_retention_policy(self, data_type: str) -> int:
"""数据留存周期"""
retention_policy = {
"个人信息": 30, # 30天
"业务数据": 365, # 1年
"日志数据": 180, # 6个月
"审计数据": 365*3 # 3年
}
return retention_policy.get(data_type, 90)def desensitize_personal_info(data: dict) -> dict:
"""个人信息脱敏"""
if "phone" in data:
data["phone"] = data["phone"][:3] + "****" + data["phone"][7:]
if "id_card" in data:
data["id_card"] = data["id_card"][:6] + "********" + data["id_card"][14:]
if "email" in data:
local, domain = data["email"].split("@")
data["email"] = local[0] + "****@" + domain
if "address" in data:
data["address"] = data["address"][:3] + "****"
return data© ProgrammerAnthony, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/ai-agent-security of ProgrammerAnthony/Expert-Coding-Harness.
Open the folder on GitHubat commit ab0b827
AI Agent Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| AI Agent Security this skillProgrammerAnthony/Expert-Coding-Harness | 235 | — | ~3k | Automated safety check: Pass | MIT | |
| Skill Scannergetsentry/skills | 1k | 4 repos | ~2.5k | Automated safety check: Warn | Apache-2.0 | |
| Forensifyalexgreensh/repo-forensics | 188 | — | ~2.5k | Automated safety check: Notes | Custom licence | |
| Hol Guardhashgraph-online/hol-guard | 815 | — | ~542 | Automated safety check: Pass | Apache-2.0 | |
| Kesekit Checkcdppcorp/KESE-KIT | 361 | — | ~1.3k | Automated safety check: Pass | MIT | |
| Setuphashgraph-online/hol-guard | 815 | — | ~443 | Automated safety check: Pass | Apache-2.0 |
getsentry/skills
Scan agent skills for security issues. An agent skill from getsentry/skills.
alexgreensh/repo-forensics
Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.
hashgraph-online/hol-guard
Run HOL Guard scanner and guard operations via uv run hol-guard.
cdppcorp/KESE-KIT
Run a pre-deployment security compliance checklist based on KISA guidelines.
hashgraph-online/hol-guard
Install or initialize HOL Guard local runtime protection for Claude Code.
openclaw/clawscan
A skill your agent uses when running or explaining the ClawScan CLI, including one-off agent-skill scans, benchmark runs, scanner fixtures, judge harness commands, env var validation, and…
ProgrammerAnthony/Expert-Coding-Harness
A skill your agent uses when 用户需要设计新系统架构、评审或优化已有系统架构、选择技术方案时。触发场景:架构分析、架构设计、系统设计、architecture、架构优化、系统架构、架构评审、架构咨询、技术方案、技术设计、如何组织代码结构、模块划分、服务拆分、数据库选型、微服务设计。
ProgrammerAnthony/Expert-Coding-Harness
A skill your agent uses when 用户要求审查代码、评估代码质量、提交 PR 前检查、发现代码有潜在问题时。触发场景:代码审查、code review、审查代码、review、检查代码、代码检查、代码质量、代码评审、这段代码有问题吗、帮我看看代码、合并前检查。
ProgrammerAnthony/Expert-Coding-Harness
A skill your agent uses when 用户需要对代码进行安全审计、发现安全漏洞、上线前安全评估、检查代码是否存在安全风险时。触发场景:代码安全审计、安全审计、白盒审计、安全扫描、漏洞检测、漏洞挖掘、SQL注入、命令注入、XSS、SSRF、反序列化、认证绕过、越权、代码安全检查、security audit、code…
ProgrammerAnthony/Expert-Coding-Harness
A skill your agent uses when 程序出现错误、异常、崩溃,或行为与预期不符,或测试失败,或无法定位问题根因时。触发场景:调试、debug、报错、错误、异常、bug、问题排查、故障排查、不工作、崩溃、无法运行、出错了、为什么不生效、运行报错、跑不起来、程序挂了。
ProgrammerAnthony/Expert-Coding-Harness
A skill your agent uses when 用户需要审查前端代码(React/Vue/Next.js/TypeScript/Tailwind等)、检查代码质量、性能问题、可维护性、安全漏洞、最佳实践落地时。触发场景:前端代码评审、前端代码优化、React/Vue代码检查、TypeScript代码审查、前端性能优化、前端安全审计、前端代码规范检查。
ProgrammerAnthony/Expert-Coding-Harness
A skill your agent uses when 用户需要优化前端性能、提升页面加载速度、减少白屏时间、优化交互流畅度、进行性能排查时。触发场景:前端性能优化、页面加载慢、白屏时间长、卡顿、LCP/FID/CLS指标优化、前端性能分析、打包体积优化。
Categories
AI Agent 安全开发与防护最佳实践,包含prompt注入防护、代码执行安全、敏感信息保护、合规审计全流程规范. An agent skill from ProgrammerAnthony/Expert-Coding-Harness. AI Agent Security is an agent skill from ProgrammerAnthony/Expert-Coding-Harness.
AI Agent Security fits situations like: tasks that involve Prompt injection and agent security.
Run `npx skills add ProgrammerAnthony/Expert-Coding-Harness --skill ai-agent-security -a claude-code`. Or copy the skill folder (skills/ai-agent-security in ProgrammerAnthony/Expert-Coding-Harness) into .claude/skills/ai-agent-security in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ProgrammerAnthony/Expert-Coding-Harness --skill ai-agent-security -a codex`. Or copy the skill folder (skills/ai-agent-security in ProgrammerAnthony/Expert-Coding-Harness) into .agents/skills/ai-agent-security in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ProgrammerAnthony/Expert-Coding-Harness --skill ai-agent-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ai-agent-security, .gemini/skills/ai-agent-security, .github/skills/ai-agent-security and .opencode/skills/ai-agent-security in your project.
SKILL.md names no scripts, command-line tools or credentials: AI Agent Security is instructions for the agent only. Our summary lists: Python 3; Docker.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
AI Agent Security is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with AI Agent Security: Skill Scanner (getsentry/skills, 1k stars), Forensify (alexgreensh/repo-forensics, 188 stars), Hol Guard (hashgraph-online/hol-guard, 815 stars) and Kesekit Check (cdppcorp/KESE-KIT, 361 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ProgrammerAnthony (a GitHub user) maintains it in ProgrammerAnthony/Expert-Coding-Harness, which has 235 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on May 11, 2026.
Source: ProgrammerAnthony/Expert-Coding-Harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.