Agent skill

Infinity

by sickn33 in sickn33/agentic-awesome-skills

Enforces a strict input boundary protocol (detect, classify, filter, verify) to ensure untrusted data never reaches business logic raw.

MITAuto-check: notesBackend & APIs

Install Infinity

skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill infinity -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sickn33/agentic-awesome-skills infinity --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/infinity .claude/skills/infinity && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
infinity
GitHub stars
47k
Used in
1 other repo
Token cost
~1.6k tokens
SKILL.md length
729 words
Files
1
Skills in repo
1,394
Repo updated
First seen
Licence
MIT

At a glance

Enforces a strict input boundary protocol (detect, classify, filter, verify) to ensure untrusted data never reaches business logic raw.

  • Works in 4 steps: Boundary Detection → Classify Each Input → Mandatory Filter Layer → …
  • Backend & APIs work in your project
  • SKILL.md covers Core Philosophy, When to Use This Skill, The Four Phases and Hard Rules (Never Violated), plus 3 more sections
  • Needs API_KEY

What it does

Infinity is an agent skill from sickn33/agentic-awesome-skills. Enforces a strict input boundary protocol (detect, classify, filter, verify) to ensure untrusted data never reaches business logic raw.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.

When your agent uses it

  • Backend & APIs work in your project

Example prompts

  • “Use the infinity skill to enforce a strict input boundary protocol (detect, classify, filter, verify) to ensure untrusted data never reaches…”
  • “/infinity”

Requirements

  • A credential in API_KEY

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Boundary Detection
  2. Classify Each Input
  3. Mandatory Filter Layer
  4. Self-Check Before Done

What it can do on your machine

Read from SKILL.md and the folder at commit 1e53ce2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Infinity loads about 1.6k tokens when it runs. Until then it costs about 36 tokens; SKILL.md has 729 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~36
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:25
    ode calls `.body`, `.params`, `.query`, `.env`, `fs.read`, or a third-party SDK response

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sickn33/agentic-awesome-skills at commit 1e53ce2, republished under its MIT licence (© sickn33). 729 words, ~1,631 tokens.

Download SKILL.mdSave it as .claude/skills/infinity/SKILL.md (or your agent's skills folder).
name
infinity
description
Enforces a strict input boundary protocol (detect, classify, filter, verify) to ensure untrusted data never reaches business logic raw.
risk
safe
source
community
date_added
2026-06-23

infinity — Input Boundary & Validation Protocol

Core Philosophy

Nothing untrusted ever reaches the core — it is stopped before contact. No external data touches the codebase raw. Every boundary where data enters the system must have a filter.

The #1 source of silent bugs, crashes, and vulnerabilities is external data that arrives in an unexpected shape and gets used directly without checking. This skill enforces a filter layer at every entry point, every time.


When to Use This Skill

  • Use when you need to handle an API response
  • Use when reading user input or adding a form handler
  • Use when working with environment variables or CLI arguments
  • Use when parsing webhooks or reading from the filesystem
  • Use when any code calls .body, .params, .query, .env, fs.read, or a third-party SDK response

The Four Phases

PHASE 1 — Boundary Detection

Before writing or modifying any code that involves external data, the AI must identify and list every entry point in scope:

  • HTTP request bodies, headers, query params
  • User form inputs and UI-submitted data
  • Environment variables and config files
  • Third-party API responses
  • Webhook payloads
  • File reads from disk
  • CLI arguments
  • Database query results from external sources
  • WebSocket messages

The AI must not write any data-handling logic until every entry point in scope is listed.


PHASE 2 — Classify Each Input

For every entry point identified, the AI classifies it into one of three trust levels:

LevelDefinitionExamples
TRUSTEDInternal constants, hardcoded values, your own compile-time configEnum values, hardcoded defaults, internal constants
SEMI-TRUSTEDYour own internal services, internal APIs, controlled infrastructureInternal microservice responses, your own database reads
UNTRUSTEDAnything from users, the internet, third parties, or the filesystemUser input, external API responses, uploaded files, env vars, CLI args

Rule: TRUSTED inputs may be used directly. SEMI-TRUSTED and UNTRUSTED inputs must pass through a filter layer before any use.

The AI outputs this classification before writing any handling code:

INFINITY — BOUNDARY MAP
─────────────────────────────────────────
Entry Point              | Trust Level  | Filter Required
─────────────────────────────────────────
req.body.email           | UNTRUSTED    | ✓ format + sanitize
process.env.API_KEY      | UNTRUSTED    | ✓ presence + non-empty
internalService.getData()| SEMI-TRUSTED | ✓ schema validate
PAGINATION_LIMIT = 20    | TRUSTED      | ✗ none needed
─────────────────────────────────────────

PHASE 3 — Mandatory Filter Layer

Every UNTRUSTED and SEMI-TRUSTED input must pass through validation before it reaches any business logic, storage, or rendering. The AI must apply the right filter type for the right context:

Type Checking

  • Verify the input is the expected type before using it
  • Never assume a string is a string, a number is a number, or an array is an array

Schema Validation

  • For objects and API responses, validate shape before accessing nested fields
  • If a required field is missing, reject — do not use a fallback that hides the problem

Sanitization

  • Strip or escape content before rendering to UI (prevent XSS)
  • Normalize strings before storage (trim whitespace, consistent casing where appropriate)

Presence & Format Checks

  • Env vars: must exist and be non-empty before use
  • IDs and tokens: must match expected format before use

Rejection Rule

  • On invalid input: reject explicitly and return a clear error
  • Never silently use bad data with a fallback
  • Never let bad data pass through to fix itself "downstream"
// WRONG — using raw input directly
const user = await db.find(req.params.id);

// RIGHT — validate before use
const id = req.params.id;
if (!id || typeof id !== 'string' || !isValidUUID(id)) {
  return res.status(400).json({ error: 'Invalid ID format' });
}
const user = await db.find(id);

Show full SKILL.md (248 more words)Show less
PHASE 4 — Self-Check Before Done

Before the AI declares any data-handling code complete, it traces each entry point and confirms:

INFINITY — VERIFICATION
─────────────────────────────────────────
Entry Point              | Filter Exists | Filter Type
─────────────────────────────────────────
req.body.email           | ✓ YES         | format + sanitize
process.env.API_KEY      | ✓ YES         | presence check
internalService.getData()| ✓ YES         | schema validation
─────────────────────────────────────────
Unfiltered inputs reaching logic: NONE ✓
─────────────────────────────────────────

If any UNTRUSTED or SEMI-TRUSTED input reaches logic, storage, or rendering without a filter — the AI flags it. It does not silently pass.


Hard Rules (Never Violated)

  • No raw external data in business logic. Ever.
  • No silent fallbacks on bad input. Reject explicitly.
  • No assuming shape. Even if the API "always" returns a string — validate it.
  • No skipping env var checks. Missing env vars must fail loudly at startup, not silently at runtime.
  • No partial filtering. If you validate presence but not format, it is not filtered.
  • No filtering in the wrong place. Filters go at the entry point — not somewhere downstream after the data has already been used once.

What This Skill Prevents

  • SQL injection via unvalidated query params
  • Crashes from unexpected API response shapes
  • XSS from unescaped user content rendered to UI
  • Silent failures from missing env variables discovered at runtime
  • Type errors from assuming external data matches expected shape
  • Security vulnerabilities from untrusted data reaching sensitive operations

Quick Reference

PhaseActionWrites Code?
1 — DetectList all entry points in scope❌ No
2 — ClassifyAssign trust level to each input❌ No
3 — FilterWrite filter layer for all UNTRUSTED + SEMI-TRUSTED✅ Yes
4 — VerifyTrace each input, confirm filter exists❌ No

Limitations

  • Does not apply to purely internal logic with no external data involvement.
  • May add verbosity to trivial scripts where strict validation is not required.

© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/infinity of sickn33/agentic-awesome-skills.

Open the folder on GitHubat commit 1e53ce2

Used in 1 other repository

We found 5 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Infinity next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Infinity compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Infinity this skillsickn33/agentic-awesome-skills47k1 repos~1.6kAutomated safety check: NotesMIT
Configuring Horizoncoollabsio/coolify63k4 repos~898Automated safety check: PassMIT
Nestjs Best Practicesrolling-scopes/rsschool-app10k6 repos~1.2kAutomated safety check: PassMIT
Sub2API AdminWei-Shaw/sub2api43k1 repos~717Automated safety check: PassLGPL-3.0
Firecrawl Build Onboardingfirecrawl/firecrawl189k1 repos~1.4kAutomated safety check: NotesISC
Obsidian BasesAtmosphere/atmosphere3.8k22 repos~3.2kAutomated safety check: PassApache-2.0

Similar skills

  • Configuring Horizon

    coollabsio/coolify

    A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.

    63k GitHub starsUsed in 4 repos~898 tokens
    Backend & APIsAuto-check passed
  • Nestjs Best Practices

    rolling-scopes/rsschool-app

    NestJS best practices and architecture patterns for building production-ready applications.

    10k GitHub starsUsed in 6 repos~1.2k tokens
    Backend & APIsAuto-check passed
  • Sub2API Admin

    Wei-Shaw/sub2api

    Manages a Sub2API deployment from the command line: accounts, redeem and invitation codes, groups, proxies, imports, exports and raw admin API calls.

    43k GitHub starsUsed in 1 repo~717 tokens
    Backend & APIsAuto-check passed
  • Firecrawl Build Onboarding

    firecrawl/firecrawl

    Gets Firecrawl working in a project: signs you in through the browser, saves FIRECRAWL_API_KEY to .env and picks the first SDK or REST path.

    189k GitHub starsUsed in 1 repo~1.4k tokens
    Backend & APIsAuto-check: notes
  • Obsidian Bases

    Atmosphere/atmosphere

    Create and edit Obsidian Bases (.base files) with views, filters, formulas, and summaries.

    3.8k GitHub starsUsed in 22 repos~3.2k tokens
    Backend & APIsAuto-check passed
  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed

More from sickn33/agentic-awesome-skills

All 1,394 skills in this repo
  • Liuguang Banlan UI

    sickn33/agentic-awesome-skills

    Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • User Thoughts Memory

    sickn33/agentic-awesome-skills

    Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Using LWC Memory and Graphs

    sickn33/agentic-awesome-skills

    Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.

    47k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Find Complementary Founders

    sickn33/agentic-awesome-skills

    Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.

    47k GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Whatsapp Cloud API

    sickn33/agentic-awesome-skills

    Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~4.5k tokens
    Auto-check passed
  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed

Categories

Questions about Infinity

What does Infinity do?

Enforces a strict input boundary protocol (detect, classify, filter, verify) to ensure untrusted data never reaches business logic raw. Infinity is an agent skill from sickn33/agentic-awesome-skills. Enforces a strict input boundary protocol (detect, classify, filter, verify) to ensure untrusted data never reaches business logic raw.

When should I use Infinity?

Infinity fits situations like: backend & APIs work in your project.

How do I install Infinity in Claude Code?

Run `npx skills add sickn33/agentic-awesome-skills --skill infinity -a claude-code`. Or copy the skill folder (skills/infinity in sickn33/agentic-awesome-skills) into .claude/skills/infinity in your project. Claude Code loads it when a task matches its description.

How do I install Infinity in Codex?

Run `npx skills add sickn33/agentic-awesome-skills --skill infinity -a codex`. Or copy the skill folder (skills/infinity in sickn33/agentic-awesome-skills) into .agents/skills/infinity in your project. Codex loads it when a task matches its description.

Can I use Infinity in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill infinity -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/infinity, .gemini/skills/infinity, .github/skills/infinity and .opencode/skills/infinity in your project.

What does Infinity need to run?

Going by SKILL.md and its folder, Infinity needs credentials named API_KEY. Our summary lists: A credential in API_KEY.

Does Infinity access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Infinity safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Infinity use?

Infinity is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Infinity use?

About 1.6k tokens (SKILL.md is roughly 6.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Infinity?

Skills that share tags, products or a category with Infinity: Configuring Horizon (coollabsio/coolify, 63k stars), Nestjs Best Practices (rolling-scopes/rsschool-app, 10k stars), Sub2API Admin (Wei-Shaw/sub2api, 43k stars) and Firecrawl Build Onboarding (firecrawl/firecrawl, 189k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Infinity?

sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,304 GitHub stars. The repository holds 1,394 skills in this directory. The repository was last updated on October 6, 2026.

Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.