Agent skill

Defense In Depth

by sandgardenhq in sandgardenhq/sgai

A skill your agent uses when invalid data causes failures deep in execution, requiring validation at multiple system layers - validates at every layer data passes through to make bugs structurally…

Custom licenceAuto-check passedSecurity

Install Defense In Depth

skills CLI
$ npx skills add sandgardenhq/sgai --skill defense-in-depth -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sandgardenhq/sgai defense-in-depth --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sandgardenhq/sgai.git skills-src && mkdir -p .claude/skills && cp -r skills-src/cmd/sgai/skel/.sgai/skills/defense-in-depth .claude/skills/defense-in-depth && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
defense-in-depth
GitHub stars
137
Used in
3 other repos
Token cost
~970 tokens
SKILL.md length
316 words
Files
1
Skills in repo
53
Repo updated
First seen
Licence
Custom licence

At a glance

A skill your agent uses when invalid data causes failures deep in execution, requiring validation at multiple system layers - validates at every layer data passes through to make bugs structurally…

  • Works in 4 steps: Trace the data flow - Where does bad… → Map all checkpoints - List every point… → Add validation at each layer - Entry,… → …
  • Invalid data causes failures deep in execution
  • SKILL.md covers Overview, Why Multiple Layers, The Four Layers and Applying the Pattern, plus 2 more sections
  • Calls git

What it does

Defense In Depth is an agent skill from sandgardenhq/sgai. Use when invalid data causes failures deep in execution, requiring validation at multiple system layers - validates at every layer data passes through to make bugs structurally impossible

Its SKILL.md is about 970 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Secure coding. It works with Git. The repository describes itself as: Sandgarden AI Software Factory.

When your agent uses it

  • Invalid data causes failures deep in execution
  • Requiring validation at multiple system layers - validates at every layer data passes through to make bugs structurally impossible

Example prompts

  • “/defense-in-depth”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Trace the data flow - Where does bad value originate? Where used?
  2. Map all checkpoints - List every point data passes through
  3. Add validation at each layer - Entry, business, environment, debug
  4. Test each layer - Try to bypass layer 1, verify layer 2 catches it

What it can do on your machine

Read from SKILL.md and the folder at commit 9efbb7b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Defense In Depth loads about 970 tokens when it runs. Until then it costs about 51 tokens; SKILL.md has 316 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~51
When it runs · the whole SKILL.md, loaded when a task matches
~970

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 316 words (~970 tokens).

“When you fix a bug caused by invalid data, adding validation at one place feels sufficient. But that single check can be bypassed by different code paths, refactoring, or mocks.”

— opening of SKILL.md by sandgardenhq, Custom licence
name
defense-in-depth

Read the full SKILL.md on GitHub

Files

Just SKILL.md in cmd/sgai/skel/.sgai/skills/defense-in-depth of sandgardenhq/sgai.

Open the folder on GitHubat commit 9efbb7b

Used in 3 other repositories

We found 4 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 3 other GitHub owners. This page covers the copy in sandgardenhq/sgai, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Defense In Depth next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Defense In Depth compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Defense In Depth this skillsandgardenhq/sgai1373 repos~970Automated safety check: PassCustom licence
Defense In Depth Validationsecondsky/claude-skills227—~1.3kAutomated safety check: PassMIT
Thorough Code Reviewpretend1111/claude-desktop-app4961 repos~502Automated safety check: PassCustom licence
Security AuditTheDecipherist/claude-code-mastery551—~1.3kAutomated safety check: NotesMIT
Humble Header Report Analystrfc-st/humble379—~3.7kAutomated safety check: PassMIT
Pre-Commit Security Scanzereight/gitlab-mcp2k1 repos~859Automated safety check: NotesMIT

Similar skills

  • Defense In Depth Validation

    secondsky/claude-skills

    Validate at every layer data passes through to make bugs impossible.

    227 GitHub stars~1.3k tokensUpdated 13 days ago
    SecurityAuto-check passed
  • Thorough Code Review

    pretend1111/claude-desktop-app

    Reviews code or recent changes for bugs, security issues, performance problems and maintainability, reporting findings by severity with the reason and a fix.

    496 GitHub starsUsed in 1 repo~502 tokens
    DevelopmentAuto-check passed
  • Security Audit

    TheDecipherist/claude-code-mastery

    Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

    551 GitHub stars~1.3k tokensUpdated 5 mo ago
    SecurityAuto-check: notes
  • Parses reports from the humble HTTP security header analyzer and explains each finding with remediation steps for DevOps teams.

    379 GitHub stars~3.7k tokensUpdated yesterday
    SecurityAuto-check passed
  • Pre-Commit Security Scan

    zereight/gitlab-mcp

    Runs a fast security sweep of recent code changes before a commit or PR, checking for leaked secrets, vulnerable dependencies, unsafe input handling and auth gaps.

    2k GitHub starsUsed in 1 repo~859 tokens
    SecurityAuto-check: notes
  • DefectDojo Vulnerability Management

    AgentSecOps/SecOpsAgentKit

    Aggregates scanner results into DefectDojo, deduplicates findings, tracks remediation SLAs and prepares compliance reports across products and pipelines.

    220 GitHub stars~2.3k tokensUpdated 5 mo ago
    SecurityAuto-check passed

More from sandgardenhq/sgai

All 53 skills in this repo
  • Root Cause Tracing

    sandgardenhq/sgai

    A skill your agent uses when errors occur deep in execution and you need to trace back to find the original trigger - systematically traces bugs backward through call stack, adding instrumentation…

    137 GitHub starsUsed in 4 repos~1.4k tokens
    Auto-check passed
  • Condition Based Waiting

    sandgardenhq/sgai

    A skill your agent uses when tests have race conditions, timing dependencies, or inconsistent pass/fail behavior - replaces arbitrary timeouts with condition polling to wait for actual state…

    137 GitHub starsUsed in 3 repos~933 tokens
    Auto-check passed
  • Agent Native Architecture

    sandgardenhq/sgai

    Build AI agents using prompt-native architecture where features are defined in prompts, not code.

    137 GitHub stars~2k tokensUpdated 20 days ago
    Auto-check passed
  • Adhoc

    sandgardenhq/sgai

    Run and manage ad-hoc AI prompts in sgai workspaces without starting a full agentic session.

    137 GitHub stars~1.2k tokensUpdated 20 days ago
    Auto-check passed
  • You must use this skill when debugging web UI bugs or testing interactive components that require multi-step browser interactions.

    137 GitHub stars~3.7k tokensUpdated 20 days ago
    Auto-check passed
  • Create Opencode Agents

    sandgardenhq/sgai

    Guide for creating custom opencode agents with proper configuration, permissions, path-based delegation, work splitting, and strict status envelopes.

    137 GitHub stars~1.8k tokensUpdated 20 days ago
    Auto-check passed

Works with

Categories

Questions about Defense In Depth

What does Defense In Depth do?

A skill your agent uses when invalid data causes failures deep in execution, requiring validation at multiple system layers - validates at every layer data passes through to make bugs structurally…. Defense In Depth is an agent skill from sandgardenhq/sgai.

When should I use Defense In Depth?

Defense In Depth fits situations like: invalid data causes failures deep in execution; requiring validation at multiple system layers - validates at every layer data passes through to make bugs structurally impossible.

How do I install Defense In Depth in Claude Code?

Run `npx skills add sandgardenhq/sgai --skill defense-in-depth -a claude-code`. Or copy the skill folder (cmd/sgai/skel/.sgai/skills/defense-in-depth in sandgardenhq/sgai) into .claude/skills/defense-in-depth in your project. Claude Code loads it when a task matches its description.

How do I install Defense In Depth in Codex?

Run `npx skills add sandgardenhq/sgai --skill defense-in-depth -a codex`. Or copy the skill folder (cmd/sgai/skel/.sgai/skills/defense-in-depth in sandgardenhq/sgai) into .agents/skills/defense-in-depth in your project. Codex loads it when a task matches its description.

Can I use Defense In Depth in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sandgardenhq/sgai --skill defense-in-depth -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/defense-in-depth, .gemini/skills/defense-in-depth, .github/skills/defense-in-depth and .opencode/skills/defense-in-depth in your project.

What does Defense In Depth need to run?

Going by SKILL.md and its folder, Defense In Depth needs the command-line tools its instructions call (git).

Does Defense In Depth access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Defense In Depth safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Defense In Depth use?

Defense In Depth has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Defense In Depth use?

About 970 tokens (SKILL.md is roughly 3.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Defense In Depth?

Skills that share tags, products or a category with Defense In Depth: Defense In Depth Validation (secondsky/claude-skills, 227 stars), Thorough Code Review (pretend1111/claude-desktop-app, 496 stars), Security Audit (TheDecipherist/claude-code-mastery, 551 stars) and Humble Header Report Analyst (rfc-st/humble, 379 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Defense In Depth?

sandgardenhq (a GitHub organization) maintains it in sandgardenhq/sgai, which has 137 GitHub stars. The repository holds 53 skills in this directory. The repository was last updated on September 21, 2026.

Source: sandgardenhq/sgai on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.