Agent skill

Raytsystem Security Review

by romarayt in romarayt/raytsystem-public-os

Audit raytsystem changes for prompt injection, provenance bypass, path/symlink/hardlink escape, secret leakage, stale fencing, partial promotion, unsafe parsing, and unapproved side effects.

Apache-2.0Auto-check passedSecurity

Install Raytsystem Security Review

skills CLI
$ npx skills add romarayt/raytsystem-public-os --skill raytsystem-security-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install romarayt/raytsystem-public-os raytsystem-security-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/romarayt/raytsystem-public-os.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/raytsystem-security-review .claude/skills/raytsystem-security-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
raytsystem-security-review
GitHub stars
149
Token cost
~572 tokens
SKILL.md length
218 words
Files
2
Skills in repo
12
Repo updated
First seen
Licence
Apache-2.0

At a glance

Audit raytsystem changes for prompt injection, provenance bypass, path/symlink/hardlink escape, secret leakage, stale fencing, partial promotion, unsafe parsing, and unapproved side effects.

  • Works in 3 steps: Run uv run raytsystem agent preflight… → Run agent subagent-check before… → Snapshot declared canonical/external…
  • SECURITY REVIEW
  • SKILL.md covers Inputs and outputs, Write scope, Preflight and Workflow, plus 3 more sections
  • Calls uv

What it does

Raytsystem Security Review is an agent skill from romarayt/raytsystem-public-os. Audit raytsystem changes for prompt injection, provenance bypass, path/symlink/hardlink escape, secret leakage, stale fencing, partial promotion, unsafe parsing, and unapproved side effects. Use for SECURITY REVIEW, adversarial testing, recovery review, or approval-boundary validation; remain independent and read-only.

Its SKILL.md is about 570 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Security, covering Security review and Prompt injection and agent security. The repository describes itself as: Local-first agent workspace for knowledge, tasks, documents and verifiable workflows · Локальная агентная система для знаний, задач и проверяемых процессов · t.me/romarayt. The licence is Apache-2.0.

When your agent uses it

  • SECURITY REVIEW
  • Adversarial testing
  • Recovery review
  • Approval-boundary validation

Example prompts

  • “/raytsystem-security-review”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Run uv run raytsystem agent preflight --skill raytsystem-security-review --write --json locally.
  2. Run agent subagent-check before delegation; hosted review receives only safe excerpts.
  3. Snapshot declared canonical/external state and identify every write/egress boundary.

What it can do on your machine

Read from SKILL.md and the folder at commit b5ac705. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • uv

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use uv, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Raytsystem Security Review loads about 572 tokens when it runs. Until then it costs about 87 tokens; SKILL.md has 218 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~87
When it runs · the whole SKILL.md, loaded when a task matches
~572

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from romarayt/raytsystem-public-os at commit b5ac705, republished under its Apache-2.0 licence (© romarayt). 218 words, ~572 tokens.

Download SKILL.mdSave it as .claude/skills/raytsystem-security-review/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
raytsystem-security-review
description
Audit raytsystem changes for prompt injection, provenance bypass, path/symlink/hardlink escape, secret leakage, stale fencing, partial promotion, unsafe parsing, and unapproved side effects. Use for SECURITY REVIEW, adversarial testing, recovery review, or approval-boundary validation; remain independent and read-only.

raytsystem Security Review

Inputs and outputs

  • Accept one bounded change/run plus threat model and declared permissions.
  • Return confirmed or unproven Critical/High findings with repro, violated invariant, and minimal regression test/fix.

Write scope

  • Keep review read-only; run only non-mutating diagnostics or isolated synthetic tests.
  • Never read secrets without scoped necessity, disclose values, promote, publish, or modify external systems.

Preflight

  1. Run uv run raytsystem agent preflight --skill raytsystem-security-review --write --json locally.
  2. Run agent subagent-check before delegation; hosted review receives only safe excerpts.
  3. Snapshot declared canonical/external state and identify every write/egress boundary.

Workflow

  1. Trace untrusted input through Fetcher/Extractor/proposal/validation/promotion/query/save paths.
  2. Test raw/hash/citation closure, generation races, lease fencing, WAL/pointer crash windows, and idempotency.
  3. Test SQL/FTS injection, resource limits, archive/parser containment, symlink/hardlink/no-follow paths, and secret redaction.
  4. Verify zero unapproved process/network/outbox/Git/external action.

Validation

  • Require a regression test for every confirmed Critical/High issue.
  • Re-run scoped and full gates after fixes; never accept skipped required tests.
  • Exercise evals m3-security-review-golden and m3-security-review-adversarial.

Recovery

  • Preserve failed staging and machine-readable reports; retry only classified transient failures.
  • On quota/tool loss, list exact reviewed surfaces and remaining adversarial cases.

Stop and approval conditions

  • Stop on secret/PII exposure, unsafe external destination, real promotion, destructive action, or missing authority.
  • Do not downgrade a confirmed issue because exploitation is inconvenient; fail closed and request the narrow required approval.

© romarayt, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/raytsystem-security-review of romarayt/raytsystem-public-os.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit b5ac705

Compare with similar skills

Raytsystem Security Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Raytsystem Security Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Raytsystem Security Review this skillromarayt/raytsystem-public-os149—~572Automated safety check: PassApache-2.0
Kesekit Checkcdppcorp/KESE-KIT360—~1.3kAutomated safety check: PassMIT
Agentic GitHub Actions Auditortrailofbits/skills7.5k6 repos~5.4kAutomated safety check: NotesCC-BY-SA-4.0
Agent Security Hardeningaffaan-m/ECC276k—~2.7kAutomated safety check: PassMIT
Slowmist Agent Securityslowmist/slowmist-agent-security508—~1.4kAutomated safety check: PassMIT
AI SAFE2 Secure Build CopilotCyberStrategyInstitute/ai-safe2-framework147—~1.2kAutomated safety check: PassCustom licence

Similar skills

  • Kesekit Check

    cdppcorp/KESE-KIT

    Run a pre-deployment security compliance checklist based on KISA guidelines.

    360 GitHub stars~1.3k tokensUpdated 6 mo ago
    SecurityAuto-check passed
  • Official

    Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.

    7.5k GitHub starsUsed in 6 repos~5.4k tokens
    SecurityAuto-check: notes
  • Security hardening guidance for AI agent frameworks that process untrusted content, invoke tools, write workspace files, manage runtime identifiers, or handle credentials.

    276k GitHub stars~2.7k tokensUpdated today
    SecurityAuto-check passed
  • Slowmist Agent Security

    slowmist/slowmist-agent-security

    Comprehensive security review framework for AI agents. An agent skill from slowmist/slowmist-agent-security.

    508 GitHub stars~1.4k tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • AI SAFE2 Secure Build Copilot

    CyberStrategyInstitute/ai-safe2-framework

    Applies the AI SAFE2 framework to security reviews, code reviews and compliance mapping for AI agents, RAG pipelines and MCP servers.

    147 GitHub stars~1.2k tokensUpdated today
    SecurityAuto-check passed
  • Secureclaw

    adversa-ai/secureclaw

    Security hardening toolkit for OpenClaw. An agent skill from adversa-ai/secureclaw.

    347 GitHub starsUsed in 1 repo~193 tokens
    SecurityAuto-check passed

More from romarayt/raytsystem-public-os

All 12 skills in this repo
  • Graph

    romarayt/raytsystem-public-os

    Refresh the raytsystem code graph so it reflects every current file, then confirm it is up to date.

    149 GitHub stars~527 tokensUpdated 2 days ago
    Auto-check passed
  • Start

    romarayt/raytsystem-public-os

    Get raytsystem running in a repository — install it if needed, then launch the interface.

    149 GitHub stars~676 tokensUpdated 2 days ago
    Auto-check passed
  • Raytsystem Watch

    romarayt/raytsystem-public-os

    Inspect video, audio, or supplied transcripts through raytsystem Tool Hub and return evidence-bound speech, visual, OCR, action, transition, and timeline findings.

    149 GitHub stars~1.6k tokensUpdated 2 days ago
    Auto-check passed
  • Raytsystem Ingest

    romarayt/raytsystem-public-os

    Capture, normalize, propose, validate, and safely promote workspace-local Markdown, text, JSON/JSONL, CSV/TSV, images, or text-bearing PDFs into raytsystem.

    149 GitHub stars~686 tokensUpdated 2 days ago
    Auto-check passed
  • Raytsystem Lint

    romarayt/raytsystem-public-os

    Run deterministic integrity, provenance, projection, link, alias, operation, and secret checks over raytsystem.

    149 GitHub stars~468 tokensUpdated 2 days ago
    Auto-check passed
  • Raytsystem Query

    romarayt/raytsystem-public-os

    Answer questions from the active raytsystem generation using local FTS5 retrieval, canonical record rehydration, verified source spans, and explicit gaps.

    149 GitHub stars~538 tokensUpdated 2 days ago
    Auto-check passed

Categories

Questions about Raytsystem Security Review

What does Raytsystem Security Review do?

Audit raytsystem changes for prompt injection, provenance bypass, path/symlink/hardlink escape, secret leakage, stale fencing, partial promotion, unsafe parsing, and unapproved side effects. Raytsystem Security Review is an agent skill from romarayt/raytsystem-public-os. Audit raytsystem changes for prompt injection, provenance bypass, path/symlink/hardlink escape, secret leakage, stale fencing, partial promotion, unsafe parsing, and unapproved side effects.

When should I use Raytsystem Security Review?

Raytsystem Security Review fits situations like: SECURITY REVIEW; adversarial testing; recovery review; approval-boundary validation.

How do I install Raytsystem Security Review in Claude Code?

Run `npx skills add romarayt/raytsystem-public-os --skill raytsystem-security-review -a claude-code`. Or copy the skill folder (skills/raytsystem-security-review in romarayt/raytsystem-public-os) into .claude/skills/raytsystem-security-review in your project. Claude Code loads it when a task matches its description.

How do I install Raytsystem Security Review in Codex?

Run `npx skills add romarayt/raytsystem-public-os --skill raytsystem-security-review -a codex`. Or copy the skill folder (skills/raytsystem-security-review in romarayt/raytsystem-public-os) into .agents/skills/raytsystem-security-review in your project. Codex loads it when a task matches its description.

Can I use Raytsystem Security Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add romarayt/raytsystem-public-os --skill raytsystem-security-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/raytsystem-security-review, .gemini/skills/raytsystem-security-review, .github/skills/raytsystem-security-review and .opencode/skills/raytsystem-security-review in your project.

What does Raytsystem Security Review need to run?

Going by SKILL.md and its folder, Raytsystem Security Review needs the command-line tools its instructions call (uv).

Does Raytsystem Security Review access the network?

SKILL.md contains no URLs. Its commands use uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Raytsystem Security Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Raytsystem Security Review use?

Raytsystem Security Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Raytsystem Security Review use?

About 572 tokens (SKILL.md is roughly 2.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Raytsystem Security Review?

Skills that share tags, products or a category with Raytsystem Security Review: Kesekit Check (cdppcorp/KESE-KIT, 360 stars), Agentic GitHub Actions Auditor (trailofbits/skills, 7.5k stars), Agent Security Hardening (affaan-m/ECC, 276k stars) and Slowmist Agent Security (slowmist/slowmist-agent-security, 508 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Raytsystem Security Review?

romarayt (a GitHub user) maintains it in romarayt/raytsystem-public-os, which has 149 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on October 8, 2026.

Source: romarayt/raytsystem-public-os on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.