Agent skill

Guard

by sharpdeveye in sharpdeveye/maestro

A skill your agent uses when deploying to production, handling sensitive data, or the workflow needs safety constraints, input validation, and security boundaries.

MITAuto-check passed

Install Guard

skills CLI
$ npx skills add sharpdeveye/maestro --skill guard -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sharpdeveye/maestro guard --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sharpdeveye/maestro.git skills-src && mkdir -p .claude/skills && cp -r skills-src/source/skills/guard .claude/skills/guard && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
guard
GitHub stars
592
Token cost
~783 tokens
SKILL.md length
232 words
Files
1
Skills in repo
25
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when deploying to production, handling sensitive data, or the workflow needs safety constraints, input validation, and security boundaries.

  • Deploying to production
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Handling sensitive data
  • The workflow needs safety constraints

What it does

Guard is an agent skill from sharpdeveye/maestro. Use when deploying to production, handling sensitive data, or the workflow needs safety constraints, input validation, and security boundaries.

Its SKILL.md is about 780 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: Workflow fluency for AI coding agents. 1 core skill · 25 commands · 7 domain references · memory layer · audit trail — works across Cursor, Claude Code, Gemini CLI, Copilot, and… The licence is MIT.

When your agent uses it

  • Deploying to production
  • Handling sensitive data
  • The workflow needs safety constraints
  • Input validation

Example prompts

  • “/guard”

What it can do on your machine

Read from SKILL.md and the folder at commit 00f9115. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Guard loads about 783 tokens when it runs. Until then it costs about 37 tokens; SKILL.md has 232 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~37
When it runs · the whole SKILL.md, loaded when a task matches
~783

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sharpdeveye/maestro at commit 00f9115, republished under its MIT licence (© sharpdeveye). 232 words, ~783 tokens.

Download SKILL.mdSave it as .claude/skills/guard/SKILL.md (or your agent's skills folder).
name
guard
description
Use when deploying to production, handling sensitive data, or the workflow needs safety constraints, input validation, and security boundaries.
argument-hint
[threat or area]
category
enhancement
version
2.0.0
user-invocable
true

MANDATORY PREPARATION

Invoke /agent-workflow — it contains workflow principles, anti-patterns, and the Context Gathering Protocol. Follow the protocol before proceeding — if no workflow context exists yet, you MUST run /teach-maestro first.

Consult the guardrails-safety reference in the agent-workflow skill for the full defense-in-depth framework.


Add safety boundaries to a workflow. Guards protect against malicious inputs, unintended outputs, data leakage, cost explosion, and all the ways an autonomous system can go wrong in the real world.

Threat Assessment

Before adding guards, understand what you're protecting against:

ThreatRisk LevelGuard Type
Prompt injectionHighInput sanitization, instruction hierarchy
PII leakageHighOutput filtering, data masking
Cost explosionHighToken budgets, rate limits
Unauthorized actionsMediumPermission scoping, confirmation gates
HallucinationMediumSource attribution, fact checking
Service abuseMediumRate limiting, authentication
Guard Implementation

Input Guards

text
Before processing any input:
1. Validate against schema (reject malformed)
2. Check size limits (reject oversized)
3. Sanitize for injection patterns
4. Rate limit check (reject if exceeded)
5. Authentication/authorization check

Output Guards

text
Before returning any output:
1. Schema validation (format correct?)
2. PII scan (names, emails, SSNs, etc.)
3. Content policy check
4. Confidence threshold check
5. Source attribution present?

Cost Guards

text
Before every model/API call:
1. Check remaining budget
2. Estimate request cost
3. If estimate > remaining budget → reject or use cheaper alternative
4. After call → update spent amount
5. Circuit breaker check (too many failures?)

Permission Guards

text
For every tool call:
1. Is this tool allowed for this user/context?
2. Is this a destructive operation? → require confirmation
3. Is this accessing data the user is authorized for?
4. Log the access for audit trail
Guard Checklist
  • All inputs validated before processing
  • PII detection on all outputs
  • Cost ceiling set with enforcement
  • Prompt injection defenses active
  • Destructive operations require confirmation
  • All access logged for audit
  • Circuit breakers on external services
  • Rate limits on all endpoints

After adding guards, run /evaluate with adversarial test scenarios to verify guards hold under attack.

NEVER:

  • Deploy without input validation
  • Trust model output for high-stakes decisions without verification
  • Run without cost controls
  • Skip logging (you need the audit trail)
  • Assume the model will follow safety instructions 100% of the time

© sharpdeveye, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in source/skills/guard of sharpdeveye/maestro.

Open the folder on GitHubat commit 00f9115

Compare with similar skills

Guard next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Guard compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Guard this skillsharpdeveye/maestro592—~783Automated safety check: PassMIT
Convex Deploy Guardopenclaw/clawhub9.5k—~885Automated safety check: NotesMIT
Deploy Setupgarrytan/gstack136k—~11kAutomated safety check: NotesMIT
Deployment Patternsaffaan-m/ECC275k1 repos~2.9kAutomated safety check: PassMIT
Vercel Deploybytedance/deer-flow83k10 repos~797Automated safety check: PassMIT
Land and Deploygarrytan/gstack136k—~18kAutomated safety check: NotesMIT

Similar skills

  • Convex Deploy Guard

    openclaw/clawhub

    Classify + announce the target Convex deployment before any deployment-affecting command; fresh explicit consent for prod actions; session read-only mode.

    9.5k GitHub stars~885 tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Deploy Setup

    garrytan/gstack

    Detects where an app deploys, its production URL and health checks, then saves the deploy configuration in CLAUDE.md for /land-and-deploy.

    136k GitHub stars~11k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Deployment iş akışları, CI/CD pipeline kalıpları, Docker konteynerizasyonu, sağlık kontrolleri, rollback stratejileri ve web uygulamaları için üretim hazırlığı kontrol listeleri.

    275k GitHub starsUsed in 1 repo~2.9k tokens
    DevOps & CloudAuto-check passed
  • Vercel Deploy

    bytedance/deer-flow

    Deploys a project to Vercel with one script and no login, then returns a live preview URL and a claim link for moving the deployment into your own Vercel account.

    83k GitHub starsUsed in 10 repos~797 tokens
    DevOps & CloudAuto-check passed
  • Land and Deploy

    garrytan/gstack

    Merges a pull request, waits for CI and the deploy, then verifies production health with canary checks, picking up where /ship leaves off.

    136k GitHub stars~18k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Covers rolling, blue-green and canary deployments, multi-stage Dockerfiles, a GitHub Actions pipeline, health checks and production readiness for web apps.

    275k GitHub starsUsed in 6 repos~2.8k tokens
    DevOps & CloudAuto-check passed

More from sharpdeveye/maestro

All 25 skills in this repo
  • Accelerate

    sharpdeveye/maestro

    A skill your agent uses when the workflow is too slow, too expensive, or both and needs latency, cost, or token usage optimization.

    592 GitHub stars~745 tokensUpdated 5 mo ago
    Auto-check passed
  • Chain

    sharpdeveye/maestro

    A skill your agent uses when the workflow needs multi-step processing with sequential, parallel, or conditional tool compositions and proper data flow.

    592 GitHub stars~607 tokensUpdated 5 mo ago
    Auto-check passed
  • Compose

    sharpdeveye/maestro

    A skill your agent uses when a single agent demonstrably cannot handle the task and multi-agent coordination is justified.

    592 GitHub stars~720 tokensUpdated 5 mo ago
    Auto-check passed
  • Diagnose

    sharpdeveye/maestro

    A skill your agent uses when the user wants to find problems, audit workflow quality, or get a comprehensive health check on their AI workflow.

    592 GitHub stars~1.5k tokensUpdated 5 mo ago
    Auto-check passed
  • Extract Pattern

    sharpdeveye/maestro

    A skill your agent uses when the user wants to create templates, extract reusable patterns, document solutions, or build a pattern library from working workflows.

    592 GitHub stars~664 tokensUpdated 5 mo ago
    Auto-check passed
  • Fortify

    sharpdeveye/maestro

    A skill your agent uses when the workflow lacks error handling, has been failing in production, or needs retry logic, fallback strategies, and circuit breakers.

    592 GitHub stars~688 tokensUpdated 5 mo ago
    Auto-check passed

Questions about Guard

What does Guard do?

A skill your agent uses when deploying to production, handling sensitive data, or the workflow needs safety constraints, input validation, and security boundaries. Guard is an agent skill from sharpdeveye/maestro. Use when deploying to production, handling sensitive data, or the workflow needs safety constraints, input validation, and security boundaries.

When should I use Guard?

Guard fits situations like: deploying to production; handling sensitive data; the workflow needs safety constraints; input validation.

How do I install Guard in Claude Code?

Run `npx skills add sharpdeveye/maestro --skill guard -a claude-code`. Or copy the skill folder (source/skills/guard in sharpdeveye/maestro) into .claude/skills/guard in your project. Claude Code loads it when a task matches its description.

How do I install Guard in Codex?

Run `npx skills add sharpdeveye/maestro --skill guard -a codex`. Or copy the skill folder (source/skills/guard in sharpdeveye/maestro) into .agents/skills/guard in your project. Codex loads it when a task matches its description.

Can I use Guard in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sharpdeveye/maestro --skill guard -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/guard, .gemini/skills/guard, .github/skills/guard and .opencode/skills/guard in your project.

What does Guard need to run?

SKILL.md names no scripts, command-line tools or credentials: Guard is instructions for the agent only.

Does Guard access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Guard safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Guard use?

Guard is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Guard use?

About 783 tokens (SKILL.md is roughly 3.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Guard?

Skills that share tags, products or a category with Guard: Convex Deploy Guard (openclaw/clawhub, 9.5k stars), Deploy Setup (garrytan/gstack, 136k stars), Deployment Patterns (affaan-m/ECC, 275k stars) and Vercel Deploy (bytedance/deer-flow, 83k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Guard?

sharpdeveye (a GitHub user) maintains it in sharpdeveye/maestro, which has 592 GitHub stars. The repository holds 25 skills in this directory. The repository was last updated on April 29, 2026.

Source: sharpdeveye/maestro on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.