AI Agent 安全开发与防护最佳实践,包含prompt注入防护、代码执行安全、敏感信息保护、合规审计全流程规范. An agent skill from ProgrammerAnthony/Expert-Coding-Harness.

MITAuto-check passedSecurity

Install AI Agent Security

skills CLI
$ npx skills add ProgrammerAnthony/Expert-Coding-Harness --skill ai-agent-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ProgrammerAnthony/Expert-Coding-Harness ai-agent-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ProgrammerAnthony/Expert-Coding-Harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/ai-agent-security .claude/skills/ai-agent-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ai-agent-security
GitHub stars
235
Token cost
~3k tokens
SKILL.md length
81 words
Files
1
Skills in repo
23
Repo updated
First seen
Licence
MIT

At a glance

AI Agent 安全开发与防护最佳实践,包含prompt注入防护、代码执行安全、敏感信息保护、合规审计全流程规范. An agent skill from ProgrammerAnthony/Expert-Coding-Harness.

  • Works in 4 steps: 输入层防护 → 生成层防护 → 执行层防护 → …
  • Tasks that involve Prompt injection and agent security
  • SKILL.md covers When to Activate, AI Agent 安全风险矩阵, 四层安全防护架构 and 合规要求实现, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

AI Agent Security is an agent skill from ProgrammerAnthony/Expert-Coding-Harness. AI Agent 安全开发与防护最佳实践,包含prompt注入防护、代码执行安全、敏感信息保护、合规审计全流程规范。

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Prompt injection and agent security. The repository describes itself as: 生产级 AI Agent 技能集,辅助AI Harness应用于企业开发,覆盖代码审查、代码安全审计、TDD、需求工程、实施计划与子代理编排、架构设计、调试、前端开发与技能创建全流程。 The licence is MIT.

When your agent uses it

  • Tasks that involve Prompt injection and agent security

Example prompts

  • “/ai-agent-security”

Requirements

  • Python 3
  • Docker

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. 输入层防护
  2. 生成层防护
  3. 执行层防护
  4. 审计层防护

What it can do on your machine

Read from SKILL.md and the folder at commit ab0b827. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are python).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

AI Agent Security loads about 3k tokens when it runs. Until then it costs about 19 tokens; SKILL.md has 81 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~19
When it runs · the whole SKILL.md, loaded when a task matches
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ProgrammerAnthony/Expert-Coding-Harness at commit ab0b827, republished under its MIT licence (© ProgrammerAnthony). 81 words, ~2,984 tokens.

Download SKILL.mdSave it as .claude/skills/ai-agent-security/SKILL.md (or your agent's skills folder).
name
ai-agent-security
description
AI Agent 安全开发与防护最佳实践,包含prompt注入防护、代码执行安全、敏感信息保护、合规审计全流程规范。
origin
迁移自Everything Claude Code AgentShield模块,适配国内等保2.0要求

AI Agent 安全开发最佳实践

本技能基于生产级AI Agent防护方案整理,覆盖AI系统全生命周期的安全风险防控,符合等保2.0三级要求与数据安全法规定。

When to Activate

  • 开发企业级AI Agent应用
  • 对接敏感内部数据的AI系统
  • 实现代码执行能力的AI助手
  • 合规审计要求的AI系统建设
  • AI安全风险评估与加固

AI Agent 安全风险矩阵

风险类型危害等级典型场景
Prompt注入攻击高危诱导Agent执行恶意指令、绕过安全限制
敏感信息泄露高危Agent输出内部数据、密钥、用户隐私
恶意代码执行极高危Agent生成并执行恶意代码,控制服务器
数据投毒中危污染训练数据/知识库,导致Agent输出错误信息
越权访问高危Agent绕过权限控制,访问未授权资源
合规风险中危违反数据安全法、个人信息保护法等法规

四层安全防护架构

1. 输入层防护
Prompt注入检测
python
from typing import List
import re

class PromptInjectionDetector:
    def __init__(self):
        self.risk_patterns = [
            # 指令绕过模式
            r"(ignore|disregard|forget).*(previous|above|prior).*(instructions|prompt|rules)",
            r"(you are|act as|pretend to be).*(not|no longer).*(assistant|AI|bot)",
            r"(override|bypass|disable).*(security|safety|content).*(filters|policies|restrictions)",
            # 系统指令模式
            r"```system\s*",
            r"<\|system\|>",
            r"SYSTEM:",
            # 诱导输出模式
            r"(output|print|reveal|disclose).*(prompt|instructions|rules|system)",
            r"(show|tell|list).*(all|full|entire).*(prompt|context|memory)"
        ]
        self.suspicious_keywords = ["jailbreak", "DAN", "dev mode", "developer mode", "unrestricted"]
    
    def detect(self, prompt: str, threshold: float = 0.7) -> dict:
        risk_score = 0.0
        matched_patterns = []
        
        # 正则匹配检测
        for pattern in self.risk_patterns:
            if re.search(pattern, prompt, re.IGNORECASE):
                risk_score += 0.2
                matched_patterns.append(pattern)
        
        # 关键词检测
        for keyword in self.suspicious_keywords:
            if keyword.lower() in prompt.lower():
                risk_score += 0.15
        
        # 特殊字符检测
        special_char_ratio = len(re.findall(r'[^\w\s,.,。?!;:""''()()、]', prompt)) / len(prompt) if prompt else 0
        if special_char_ratio > 0.3:
            risk_score += 0.25
        
        return {
            "is_risk": risk_score >= threshold,
            "risk_score": risk_score,
            "matched_patterns": matched_patterns
        }

# 使用示例
detector = PromptInjectionDetector()
result = detector.detect(user_input)
if result["is_risk"]:
    raise SecurityError("疑似Prompt注入攻击,请求已拦截")
输入规范化
python
def normalize_input(prompt: str) -> str:
    # 移除特殊标记
    prompt = re.sub(r'<\|.*?\|>', '', prompt)
    # 移除系统指令关键词
    prompt = re.sub(r'(?i)\b(system|assistant|user):\s*', '', prompt)
    # 移除代码块标记
    prompt = re.sub(r'```[\s\S]*?```', '[CODE_BLOCK_REMOVED]', prompt)
    # 截断过长输入
    if len(prompt) > 4000:
        prompt = prompt[:4000] + "[TRUNCATED]"
    return prompt
2. 生成层防护
输出校验
python
import re
from typing import List

class OutputValidator:
    def __init__(self):
        self.sensitive_patterns = [
            # 密钥模式
            r'(sk_|api_key|secret|token|password)\s*[:=]\s*[\w-]+',
            # 隐私数据模式
            r'\b\d{11}\b',  # 手机号
            r'\b\d{18}\b',  # 身份证号
            r'\b[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\.[A-Z|a-z]{2,}\b',  # 邮箱
            # 内部信息模式
            r'(内部|机密|绝密|保密|敏感)',
            r'(内网|192\.168\.|10\.|172\.1[6-9]\.|172\.2[0-9]\.|172\.3[0-1]\.)'
        ]
    
    def validate(self, output: str) -> dict:
        risks = []
        cleaned_output = output
        
        # 敏感信息检测与脱敏
        for pattern in self.sensitive_patterns:
            matches = re.findall(pattern, output, re.IGNORECASE)
            if matches:
                risks.append(f"检测到敏感信息: {pattern}")
                # 脱敏处理
                cleaned_output = re.sub(pattern, '***', cleaned_output, flags=re.IGNORECASE)
        
        # 恶意代码检测
        malicious_code_patterns = [
            r'(rm\s+-rf|format\s+/|del\s+/f/s/q|reg\s+delete)',
            r'(curl|wget).*http.*\|.*sh',
            r'(eval|exec|system|popen|subprocess\.call)',
            r'(base64.*\|.*bash|bash.*<\(curl)'
        ]
        
        for pattern in malicious_code_patterns:
            if re.search(pattern, output, re.IGNORECASE):
                risks.append(f"检测到恶意代码: {pattern}")
                cleaned_output = "输出包含恶意代码,已拦截"
                break
        
        return {
            "is_risk": len(risks) > 0,
            "risks": risks,
            "cleaned_output": cleaned_output
        }
幻觉检测
python
def verify_facts(output: str, knowledge_base: List[str]) -> dict:
    """基于知识库验证输出事实正确性"""
    import spacy
    nlp = spacy.load("zh_core_web_sm")
    
    doc = nlp(output)
    facts = [ent.text for ent in doc.ents if ent.label_ in ["PERSON", "ORG", "DATE", "EVENT"]]
    
    unverified_facts = []
    for fact in facts:
        if not any(fact in kb_entry for kb_entry in knowledge_base):
            unverified_facts.append(fact)
    
    return {
        "has_hallucination": len(unverified_facts) > 0,
        "unverified_facts": unverified_facts,
        "confidence": 1.0 - (len(unverified_facts) / max(len(facts), 1))
    }
3. 执行层防护
代码执行沙箱
python
import subprocess
import tempfile
import os
from pathlib import Path

class CodeSandbox:
    def __init__(self, memory_limit: str = "256m", cpu_limit: float = 0.5, timeout: int = 10):
        self.memory_limit = memory_limit
        self.cpu_limit = cpu_limit
        self.timeout = timeout
    
    def execute(self, code: str, language: str = "python") -> dict:
        # 创建临时目录
        with tempfile.TemporaryDirectory() as tmpdir:
            tmpdir = Path(tmpdir)
            
            # 写入代码文件
            code_file = tmpdir / "code"
            code_file.write_text(code)
            
            try:
                if language == "python":
                    cmd = [
                        "docker", "run", "--rm",
                        "--memory", self.memory_limit,
                        "--cpus", str(self.cpu_limit),
                        "--network", "none",  # 禁用网络
                        "--read-only",        # 只读文件系统
                        "-v", f"{tmpdir}:/app",
                        "python:3.11-slim",
                        "python", "/app/code"
                    ]
                elif language == "javascript":
                    cmd = [
                        "docker", "run", "--rm",
                        "--memory", self.memory_limit,
                        "--cpus", str(self.cpu_limit),
                        "--network", "none",
                        "--read-only",
                        "-v", f"{tmpdir}:/app",
                        "node:20-slim",
                        "node", "/app/code"
                    ]
                else:
                    return {"error": "不支持的语言"}
                
                # 执行代码
                result = subprocess.run(
                    cmd,
                    capture_output=True,
                    text=True,
                    timeout=self.timeout
                )
                
                return {
                    "success": result.returncode == 0,
                    "stdout": result.stdout,
                    "stderr": result.stderr,
                    "returncode": result.returncode
                }
                
            except subprocess.TimeoutExpired:
                return {"error": "执行超时"}
            except Exception as e:
                return {"error": f"执行错误: {str(e)}"}
工具调用权限控制
python
from typing import Dict, List, Callable

class ToolAuthorization:
    def __init__(self):
        # 角色-权限映射
        self.role_permissions: Dict[str, List[str]] = {
            "admin": ["*"],
            "developer": ["code_execute", "git_*", "database_query"],
            "user": ["web_search", "file_read", "calculator"]
        }
        # 工具风险等级
        self.tool_risk: Dict[str, str] = {
            "code_execute": "high",
            "database_write": "high",
            "file_delete": "high",
            "email_send": "medium",
            "web_search": "low",
            "calculator": "low"
        }
    
    def check_permission(self, user_role: str, tool_name: str) -> bool:
        permissions = self.role_permissions.get(user_role, [])
        
        # 通配符匹配
        for perm in permissions:
            if perm == "*":
                return True
            if perm.endswith("*") and tool_name.startswith(perm[:-1]):
                return True
            if perm == tool_name:
                return True
        
        return False
    
    def require_mfa(self, tool_name: str) -> bool:
        """高风险工具需要二次验证"""
        return self.tool_risk.get(tool_name, "low") == "high"
4. 审计层防护
全链路审计日志
python
import json
from datetime import datetime
from typing import Any

class AuditLogger:
    def __init__(self, log_path: str = "audit.log"):
        self.log_path = log_path
    
    def log_event(self, 
                 event_type: str,
                 user_id: str,
                 session_id: str,
                 tool_name: str = None,
                 input_data: Any = None,
                 output_data: Any = None,
                 is_risk: bool = False,
                 risk_details: List[str] = None):
        event = {
            "timestamp": datetime.utcnow().isoformat(),
            "event_type": event_type,
            "user_id": user_id,
            "session_id": session_id,
            "tool_name": tool_name,
            "input_hash": hash(str(input_data)) if input_data else None,
            "output_hash": hash(str(output_data)) if output_data else None,
            "is_risk": is_risk,
            "risk_details": risk_details or []
        }
        
        with open(self.log_path, "a", encoding="utf-8") as f:
            f.write(json.dumps(event, ensure_ascii=False) + "\n")

# 使用示例
audit_logger = AuditLogger()
audit_logger.log_event(
    event_type="tool_call",
    user_id="user123",
    session_id="session456",
    tool_name="code_execute",
    input_data=user_code,
    output_data=execution_result,
    is_risk=False
)

合规要求实现

数据安全法合规
python
class DataCompliance:
    def __init__(self):
        self.sensitive_data_types = ["个人信息", "隐私数据", "商业秘密", "重要数据"]
    
    def data_processing_approval(self, data_type: str, processing_purpose: str) -> bool:
        """数据处理审批流程"""
        if data_type in self.sensitive_data_types:
            # 需要审批流程
            return self.check_approval_flow(data_type, processing_purpose)
        return True
    
    def data_retention_policy(self, data_type: str) -> int:
        """数据留存周期"""
        retention_policy = {
            "个人信息": 30,  # 30天
            "业务数据": 365,  # 1年
            "日志数据": 180,  # 6个月
            "审计数据": 365*3  # 3年
        }
        return retention_policy.get(data_type, 90)
个人信息保护法合规
python
def desensitize_personal_info(data: dict) -> dict:
    """个人信息脱敏"""
    if "phone" in data:
        data["phone"] = data["phone"][:3] + "****" + data["phone"][7:]
    if "id_card" in data:
        data["id_card"] = data["id_card"][:6] + "********" + data["id_card"][14:]
    if "email" in data:
        local, domain = data["email"].split("@")
        data["email"] = local[0] + "****@" + domain
    if "address" in data:
        data["address"] = data["address"][:3] + "****"
    return data

AI Agent安全检查清单

开发阶段
  • 实现Prompt注入检测与防护
  • 输出敏感信息自动脱敏
  • 代码执行能力通过沙箱隔离
  • 工具调用实现最小权限控制
  • 高风险操作需要二次验证
  • 全链路审计日志完备
  • 敏感数据加密存储与传输
测试阶段
  • 完成Prompt注入攻击测试(覆盖常见攻击模式)
  • 完成敏感信息泄露测试
  • 完成恶意代码执行测试
  • 完成越权访问测试
  • 性能压测下安全防护不失效
  • 异常场景下安全策略不绕过
运行阶段
  • 安全规则实时更新
  • 异常行为实时告警
  • 定期安全审计与漏洞扫描
  • 数据定期备份与恢复演练
  • 安全事件应急响应流程完备
  • 定期安全培训与意识提升

© ProgrammerAnthony, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/ai-agent-security of ProgrammerAnthony/Expert-Coding-Harness.

Open the folder on GitHubat commit ab0b827

Compare with similar skills

AI Agent Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

AI Agent Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
AI Agent Security this skillProgrammerAnthony/Expert-Coding-Harness235—~3kAutomated safety check: PassMIT
Skill Scannergetsentry/skills1k4 repos~2.5kAutomated safety check: WarnApache-2.0
Forensifyalexgreensh/repo-forensics188—~2.5kAutomated safety check: NotesCustom licence
Hol Guardhashgraph-online/hol-guard815—~542Automated safety check: PassApache-2.0
Kesekit Checkcdppcorp/KESE-KIT361—~1.3kAutomated safety check: PassMIT
Setuphashgraph-online/hol-guard815—~443Automated safety check: PassApache-2.0

Similar skills

  • Skill Scanner

    getsentry/skills

    Official

    Scan agent skills for security issues. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.5k tokens
    SecurityAuto-check: warnings
  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    188 GitHub stars~2.5k tokensUpdated 10 days ago
    SecurityAuto-check: notes
  • Hol Guard

    hashgraph-online/hol-guard

    Run HOL Guard scanner and guard operations via uv run hol-guard.

    815 GitHub stars~542 tokensUpdated today
    SecurityAuto-check passed
  • Kesekit Check

    cdppcorp/KESE-KIT

    Run a pre-deployment security compliance checklist based on KISA guidelines.

    361 GitHub stars~1.3k tokensUpdated 6 mo ago
    SecurityAuto-check passed
  • Setup

    hashgraph-online/hol-guard

    Install or initialize HOL Guard local runtime protection for Claude Code.

    815 GitHub stars~443 tokensUpdated today
    SecurityAuto-check passed
  • Clawscan CLI

    openclaw/clawscan

    A skill your agent uses when running or explaining the ClawScan CLI, including one-off agent-skill scans, benchmark runs, scanner fixtures, judge harness commands, env var validation, and…

    142 GitHub stars~3k tokensUpdated today
    SecurityAuto-check passed

More from ProgrammerAnthony/Expert-Coding-Harness

All 23 skills in this repo
  • Architecture Advisor

    ProgrammerAnthony/Expert-Coding-Harness

    A skill your agent uses when 用户需要设计新系统架构、评审或优化已有系统架构、选择技术方案时。触发场景:架构分析、架构设计、系统设计、architecture、架构优化、系统架构、架构评审、架构咨询、技术方案、技术设计、如何组织代码结构、模块划分、服务拆分、数据库选型、微服务设计。

    235 GitHub stars~673 tokensUpdated 4 mo ago
    Auto-check passed
  • Code Review Expert

    ProgrammerAnthony/Expert-Coding-Harness

    A skill your agent uses when 用户要求审查代码、评估代码质量、提交 PR 前检查、发现代码有潜在问题时。触发场景:代码审查、code review、审查代码、review、检查代码、代码检查、代码质量、代码评审、这段代码有问题吗、帮我看看代码、合并前检查。

    235 GitHub stars~806 tokensUpdated 4 mo ago
    Auto-check passed
  • Code Security Audit

    ProgrammerAnthony/Expert-Coding-Harness

    A skill your agent uses when 用户需要对代码进行安全审计、发现安全漏洞、上线前安全评估、检查代码是否存在安全风险时。触发场景:代码安全审计、安全审计、白盒审计、安全扫描、漏洞检测、漏洞挖掘、SQL注入、命令注入、XSS、SSRF、反序列化、认证绕过、越权、代码安全检查、security audit、code…

    235 GitHub stars~1.6k tokensUpdated 4 mo ago
    Auto-check passed
  • Debug Expert

    ProgrammerAnthony/Expert-Coding-Harness

    A skill your agent uses when 程序出现错误、异常、崩溃,或行为与预期不符,或测试失败,或无法定位问题根因时。触发场景:调试、debug、报错、错误、异常、bug、问题排查、故障排查、不工作、崩溃、无法运行、出错了、为什么不生效、运行报错、跑不起来、程序挂了。

    235 GitHub stars~986 tokensUpdated 4 mo ago
    Auto-check passed
  • Frontend Code Review

    ProgrammerAnthony/Expert-Coding-Harness

    A skill your agent uses when 用户需要审查前端代码(React/Vue/Next.js/TypeScript/Tailwind等)、检查代码质量、性能问题、可维护性、安全漏洞、最佳实践落地时。触发场景:前端代码评审、前端代码优化、React/Vue代码检查、TypeScript代码审查、前端性能优化、前端安全审计、前端代码规范检查。

    235 GitHub stars~614 tokensUpdated 4 mo ago
    Auto-check passed
  • Frontend Performance Optimization

    ProgrammerAnthony/Expert-Coding-Harness

    A skill your agent uses when 用户需要优化前端性能、提升页面加载速度、减少白屏时间、优化交互流畅度、进行性能排查时。触发场景:前端性能优化、页面加载慢、白屏时间长、卡顿、LCP/FID/CLS指标优化、前端性能分析、打包体积优化。

    235 GitHub stars~701 tokensUpdated 4 mo ago
    Auto-check passed

Categories

Questions about AI Agent Security

What does AI Agent Security do?

AI Agent 安全开发与防护最佳实践,包含prompt注入防护、代码执行安全、敏感信息保护、合规审计全流程规范. An agent skill from ProgrammerAnthony/Expert-Coding-Harness. AI Agent Security is an agent skill from ProgrammerAnthony/Expert-Coding-Harness.

When should I use AI Agent Security?

AI Agent Security fits situations like: tasks that involve Prompt injection and agent security.

How do I install AI Agent Security in Claude Code?

Run `npx skills add ProgrammerAnthony/Expert-Coding-Harness --skill ai-agent-security -a claude-code`. Or copy the skill folder (skills/ai-agent-security in ProgrammerAnthony/Expert-Coding-Harness) into .claude/skills/ai-agent-security in your project. Claude Code loads it when a task matches its description.

How do I install AI Agent Security in Codex?

Run `npx skills add ProgrammerAnthony/Expert-Coding-Harness --skill ai-agent-security -a codex`. Or copy the skill folder (skills/ai-agent-security in ProgrammerAnthony/Expert-Coding-Harness) into .agents/skills/ai-agent-security in your project. Codex loads it when a task matches its description.

Can I use AI Agent Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ProgrammerAnthony/Expert-Coding-Harness --skill ai-agent-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ai-agent-security, .gemini/skills/ai-agent-security, .github/skills/ai-agent-security and .opencode/skills/ai-agent-security in your project.

What does AI Agent Security need to run?

SKILL.md names no scripts, command-line tools or credentials: AI Agent Security is instructions for the agent only. Our summary lists: Python 3; Docker.

Does AI Agent Security access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is AI Agent Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does AI Agent Security use?

AI Agent Security is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does AI Agent Security use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to AI Agent Security?

Skills that share tags, products or a category with AI Agent Security: Skill Scanner (getsentry/skills, 1k stars), Forensify (alexgreensh/repo-forensics, 188 stars), Hol Guard (hashgraph-online/hol-guard, 815 stars) and Kesekit Check (cdppcorp/KESE-KIT, 361 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains AI Agent Security?

ProgrammerAnthony (a GitHub user) maintains it in ProgrammerAnthony/Expert-Coding-Harness, which has 235 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on May 11, 2026.

Source: ProgrammerAnthony/Expert-Coding-Harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.