Agent skill

Zero Trust

by sickn33 in sickn33/agentic-awesome-skills

Implement zero-trust network architecture. An agent skill from sickn33/agentic-awesome-skills.

MITAuto-check passedBackend & APIs

Install Zero Trust

skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill zero-trust -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sickn33/agentic-awesome-skills zero-trust --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/zero-trust .claude/skills/zero-trust && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
zero-trust
GitHub stars
47k
Used in
2 other repos
Token cost
~3.2k tokens
SKILL.md length
368 words
Files
1
Skills in repo
1,394
Repo updated
First seen
Licence
MIT

At a glance

Implement zero-trust network architecture. An agent skill from sickn33/agentic-awesome-skills.

  • Works in 8 steps: Inventory assets and data flows - Map… → Deploy identity provider - Centralize… → Implement identity-aware proxy - Route… → …
  • Implementing modern security architectures
  • SKILL.md covers When to Use This Skill, Prerequisites, Core Principles and BeyondCorp Implementation, plus 8 more sections
  • Calls curl and kubectl; reaches api.cloudflare.com and accounts.google.com; needs CF_TOKEN and CLIENT_SECRET

What it does

Zero Trust is an agent skill from sickn33/agentic-awesome-skills. Implement zero-trust network architecture. Configure identity-based access, micro-segmentation, and continuous verification. Use when implementing modern security architectures.

Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Requires the relevant security tooling (scanners, vault CLIs) and an authorized scope for any active assessment. Docs-only; helper scripts and templates not…

It sits in Backend & APIs. It works with Cloudflare. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.

When your agent uses it

  • Implementing modern security architectures

Example prompts

  • “/zero-trust”

Requirements

  • A credential in CLIENT_SECRET
  • A credential in COOKIE_SECRET
  • Compatibility (from SKILL.md): Requires the relevant security tooling (scanners, vault CLIs) and an authorized scope for any active assessment. Docs-only; helper scripts and templates not bundled.

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. Inventory assets and data flows - Map every application, service, and data store
  2. Deploy identity provider - Centralize authentication with SSO and MFA
  3. Implement identity-aware proxy - Route all access through authentication layer
  4. Enable mTLS for service mesh - Encrypt and authenticate all service communication
  5. Apply network policies - Default deny with explicit allow rules
  6. Add device posture checks - Verify device compliance before granting access
  7. Deploy continuous monitoring - Log and analyze all access decisions
  8. Iterate and refine - Review policies based on monitoring data

What it can do on your machine

Read from SKILL.md and the folder at commit 1e53ce2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • kubectl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.cloudflare.com
    • accounts.google.com
    • internal-service.default.svc

    Also links to:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • CF_TOKEN
    • CLIENT_SECRET
    • COOKIE_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires the relevant security tooling (scanners, vault CLIs) and an authorized scope for any active assessment. Docs-only; helper scripts and templates not bundled.

    From compatibility in the SKILL.md frontmatter.

Context cost

Zero Trust loads about 3.2k tokens when it runs. Until then it costs about 47 tokens; SKILL.md has 368 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~47
When it runs · the whole SKILL.md, loaded when a task matches
~3.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sickn33/agentic-awesome-skills at commit 1e53ce2, republished under its MIT licence (© sickn33). 368 words, ~3,243 tokens.

Download SKILL.mdSave it as .claude/skills/zero-trust/SKILL.md (or your agent's skills folder).
name
zero-trust
description
Implement zero-trust network architecture. Configure identity-based access, micro-segmentation, and continuous verification. Use when implementing modern security architectures.
compatibility
Requires the relevant security tooling (scanners, vault CLIs) and an authorized scope for any active assessment. Docs-only; helper scripts and templates not bundled.
category
security
risk
critical
source
https://github.com/BagelHole/DevOps-Security-Agent-Skills
source_repo
BagelHole/DevOps-Security-Agent-Skills
source_type
community
date_added
2026-09-20
license
MIT
license_source
https://github.com/BagelHole/DevOps-Security-Agent-Skills/blob/main/LICENSE
metadata.author
devops-skills
metadata.version
1.0

Zero Trust Architecture

Implement "never trust, always verify" security model.

When to Use This Skill

Use this skill when:

  • Replacing traditional perimeter-based VPN access models
  • Implementing BeyondCorp-style access to internal applications
  • Securing multi-cloud or hybrid-cloud environments
  • Enforcing identity-based access for every service interaction
  • Meeting compliance requirements for continuous verification and least privilege
  • Adopting micro-segmentation for Kubernetes or cloud workloads

Prerequisites

  • Identity provider (IdP) supporting OIDC/SAML (Okta, Azure AD, Google Workspace)
  • Service mesh or proxy infrastructure (Istio, Envoy, Cloudflare Access)
  • Device management/MDM solution for device posture checks
  • Kubernetes cluster for workload-level examples
  • Understanding of mTLS, RBAC, and network policies

Core Principles

yaml
zero_trust_principles:
  verify_explicitly:
    description: "Authenticate and authorize every access request"
    controls:
      - Strong multi-factor authentication
      - Identity-aware proxy for all applications
      - Service-to-service mTLS
      - API token validation on every request

  least_privilege:
    description: "Grant minimum access needed for the task"
    controls:
      - Just-in-time (JIT) access provisioning
      - Time-bounded access grants
      - Role-based access with fine-grained permissions
      - Regular access reviews and certification

  assume_breach:
    description: "Design systems expecting compromise has occurred"
    controls:
      - Micro-segmentation between all services
      - End-to-end encryption (data in transit and at rest)
      - Continuous monitoring and anomaly detection
      - Blast radius containment

BeyondCorp Implementation

Cloudflare Access Configuration
bash
# Create an Access application for an internal service
curl -X POST "https://api.cloudflare.com/client/v4/accounts/${ACCOUNT_ID}/access/apps" \
  -H "Authorization: Bearer ${CF_TOKEN}" \
  -H "Content-Type: application/json" \
  -d '{
    "name": "Internal Dashboard",
    "domain": "dashboard.internal.example.com",
    "type": "self_hosted",
    "session_duration": "12h",
    "auto_redirect_to_identity": true,
    "allowed_idps": ["google-workspace-idp-id"]
  }'

# Create an Access policy
curl -X POST "https://api.cloudflare.com/client/v4/accounts/${ACCOUNT_ID}/access/apps/${APP_ID}/policies" \
  -H "Authorization: Bearer ${CF_TOKEN}" \
  -H "Content-Type: application/json" \
  -d '{
    "name": "Engineering team access",
    "decision": "allow",
    "include": [
      { "group": { "id": "engineering-group-id" } }
    ],
    "require": [
      { "login_method": { "id": "google-workspace-idp-id" } }
    ],
    "exclude": [
      { "geo": { "country_code": "KP" } }
    ]
  }'

# Create a device posture rule
curl -X POST "https://api.cloudflare.com/client/v4/accounts/${ACCOUNT_ID}/devices/posture" \
  -H "Authorization: Bearer ${CF_TOKEN}" \
  -H "Content-Type: application/json" \
  -d '{
    "name": "Require disk encryption",
    "type": "disk_encryption",
    "match": { "platform": "linux" },
    "schedule": "1h",
    "input": { "requireAll": true }
  }'
Cloudflare Access Terraform
hcl
resource "cloudflare_access_application" "dashboard" {
  account_id       = var.cloudflare_account_id
  name             = "Internal Dashboard"
  domain           = "dashboard.internal.example.com"
  type             = "self_hosted"
  session_duration = "12h"

  auto_redirect_to_identity = true
}

resource "cloudflare_access_policy" "engineering" {
  account_id     = var.cloudflare_account_id
  application_id = cloudflare_access_application.dashboard.id
  name           = "Engineering team"
  precedence     = 1
  decision       = "allow"

  include {
    group = [cloudflare_access_group.engineering.id]
  }

  require {
    login_method = [var.google_idp_id]
  }
}

resource "cloudflare_access_group" "engineering" {
  account_id = var.cloudflare_account_id
  name       = "Engineering"

  include {
    email_domain = ["example.com"]
  }

  require {
    group = ["engineering@example.com"]
  }
}

Identity-Aware Proxy with OAuth2 Proxy

yaml
# oauth2-proxy deployment for protecting internal services
apiVersion: apps/v1
kind: Deployment
metadata:
  name: oauth2-proxy
  namespace: auth
spec:
  replicas: 2
  selector:
    matchLabels:
      app: oauth2-proxy
  template:
    metadata:
      labels:
        app: oauth2-proxy
    spec:
      containers:
        - name: oauth2-proxy
          image: quay.io/oauth2-proxy/oauth2-proxy:v7.6.0
          args:
            - --provider=oidc
            - --oidc-issuer-url=https://accounts.google.com
            - --client-id=$(CLIENT_ID)
            - --client-secret=$(CLIENT_SECRET)
            - --email-domain=example.com
            - --upstream=http://internal-service.default.svc:8080
            - --http-address=0.0.0.0:4180
            - --cookie-secret=$(COOKIE_SECRET)
            - --cookie-secure=true
            - --cookie-httponly=true
            - --cookie-samesite=lax
            - --set-xauthrequest=true
            - --pass-access-token=true
            - --skip-provider-button=true
            - --session-store-type=redis
            - --redis-connection-url=redis://redis.auth.svc:6379
          env:
            - name: CLIENT_ID
              valueFrom:
                secretKeyRef:
                  name: oauth2-proxy
                  key: client-id
            - name: CLIENT_SECRET
              valueFrom:
                secretKeyRef:
                  name: oauth2-proxy
                  key: client-secret
            - name: COOKIE_SECRET
              valueFrom:
                secretKeyRef:
                  name: oauth2-proxy
                  key: cookie-secret
          ports:
            - containerPort: 4180
---
# Ingress routing through oauth2-proxy
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: internal-service
  annotations:
    nginx.ingress.kubernetes.io/auth-url: "https://auth.example.com/oauth2/auth"
    nginx.ingress.kubernetes.io/auth-signin: "https://auth.example.com/oauth2/start?rd=$scheme://$host$request_uri"
    nginx.ingress.kubernetes.io/auth-response-headers: "X-Auth-Request-User,X-Auth-Request-Email"
spec:
  rules:
    - host: dashboard.example.com
      http:
        paths:
          - path: /
            pathType: Prefix
            backend:
              service:
                name: internal-service
                port:
                  number: 8080

Service Mesh mTLS (Istio)

yaml
# Enforce strict mTLS across the mesh
apiVersion: security.istio.io/v1beta1
kind: PeerAuthentication
metadata:
  name: default
  namespace: istio-system
spec:
  mtls:
    mode: STRICT
---
# Authorization policy: frontend can call backend
apiVersion: security.istio.io/v1beta1
kind: AuthorizationPolicy
metadata:
  name: backend-access
  namespace: default
spec:
  selector:
    matchLabels:
      app: backend
  action: ALLOW
  rules:
    - from:
        - source:
            principals: ["cluster.local/ns/default/sa/frontend"]
      to:
        - operation:
            methods: ["GET", "POST"]
            paths: ["/api/*"]
---
# Default deny all in namespace
apiVersion: security.istio.io/v1beta1
kind: AuthorizationPolicy
metadata:
  name: deny-all
  namespace: production
spec: {}

Micro-Segmentation with Kubernetes Network Policies

yaml
# Default deny all traffic in namespace
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
  name: default-deny-all
  namespace: production
spec:
  podSelector: {}
  policyTypes:
    - Ingress
    - Egress
---
# Allow DNS resolution for all pods
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
  name: allow-dns
  namespace: production
spec:
  podSelector: {}
  policyTypes:
    - Egress
  egress:
    - to: []
      ports:
        - protocol: UDP
          port: 53
        - protocol: TCP
          port: 53
---
# Frontend: allow ingress from ingress controller, egress to backend
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
  name: frontend-policy
  namespace: production
spec:
  podSelector:
    matchLabels:
      app: frontend
  policyTypes:
    - Ingress
    - Egress
  ingress:
    - from:
        - namespaceSelector:
            matchLabels:
              name: ingress-nginx
      ports:
        - protocol: TCP
          port: 8080
  egress:
    - to:
        - podSelector:
            matchLabels:
              app: backend
      ports:
        - protocol: TCP
          port: 8080
---
# Database: allow from backend only, no egress
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
  name: database-policy
  namespace: production
spec:
  podSelector:
    matchLabels:
      app: database
  policyTypes:
    - Ingress
    - Egress
  ingress:
    - from:
        - podSelector:
            matchLabels:
              app: backend
      ports:
        - protocol: TCP
          port: 5432

OPA Policy for Access Decisions

rego
# policy.rego - Zero trust access decision
package zerotrust.access

import rego.v1

default allow := false

allow if {
    identity_verified
    device_compliant
    authorized_for_resource
    risk_acceptable
}

identity_verified if {
    input.identity.authenticated == true
    input.identity.mfa_verified == true
    time.now_ns() < input.identity.session_expires_ns
}

device_compliant if {
    input.device.encryption_enabled == true
    input.device.os_updated == true
    input.device.firewall_enabled == true
    input.device.certificate_valid == true
}

authorized_for_resource if {
    some role in input.identity.roles
    some permission in data.role_permissions[role]
    permission == input.resource.required_permission
}

risk_acceptable if {
    input.risk.score < 70
    not input.risk.active_threat
}

step_up_required if {
    input.risk.score >= 50
    input.risk.score < 70
    not input.identity.recent_mfa
}

Implementation Steps

  1. Inventory assets and data flows - Map every application, service, and data store
  2. Deploy identity provider - Centralize authentication with SSO and MFA
  3. Implement identity-aware proxy - Route all access through authentication layer
  4. Enable mTLS for service mesh - Encrypt and authenticate all service communication
  5. Apply network policies - Default deny with explicit allow rules
  6. Add device posture checks - Verify device compliance before granting access
  7. Deploy continuous monitoring - Log and analyze all access decisions
  8. Iterate and refine - Review policies based on monitoring data
Show full SKILL.md (153 more words)Show less

Troubleshooting

ProblemCauseSolution
Users cannot access internal appsIdentity provider misconfiguredVerify OIDC/SAML settings; check redirect URIs
mTLS connections failingCertificate expired or wrong CACheck cert expiry with istioctl proxy-config secret; verify CA chain
Network policy blocking legitimate trafficMissing egress or ingress ruleUse kubectl describe networkpolicy; verify pod labels match selectors
Device posture check failsMDM agent not reportingVerify device agent is running; check compliance dashboard
OAuth2 proxy returns 403User email domain not in allow-listAdd domain to --email-domain flag or update group membership
  • service-mesh (service-mesh) - mTLS implementation
  • kubernetes-hardening (kubernetes-hardening) - K8s security
  • vpn-setup (vpn-setup) - Traditional VPN (contrast with zero trust)

Limitations

  • Apply guidance only within authorized scope; test destructive steps in non-production first.
  • Docs-only import: upstream scripts and templates not bundled.
Example
bash
# Read-only first: inventory before any active step.
which <tool> && <tool> --help | head -n 20

Adapted from BagelHole/DevOps-Security-Agent-Skills (MIT); frontmatter, When to Use/Limitations, and safety boundaries added for upstream compliance. Docs-only import: helper scripts and templates not bundled.

© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/zero-trust of sickn33/agentic-awesome-skills.

Open the folder on GitHubat commit 1e53ce2

Used in 2 other repositories

We found 6 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Zero Trust next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Zero Trust compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Zero Trust this skillsickn33/agentic-awesome-skills47k2 repos~3.2kAutomated safety check: PassMIT
Golivemikehasa/golive-skill1.2k—~13kAutomated safety check: NotesMIT
Wranglerhodgef/apiker1275 repos~4.6kAutomated safety check: PassMIT
Cloudflare Onehodgef/apiker1272 repos~5.6kAutomated safety check: PassMIT
Nest Devicessundial-org/awesome-openclaw-skills663—~2.3kAutomated safety check: NotesNone
Cloudflareericrisco/rsc-harness156—~2.6kAutomated safety check: PassMIT

Similar skills

  • Golive

    mikehasa/golive-skill

    Take an agent-written app from repo to live production on the user's OWN accounts, with providers they choose (hosting, database, auth, payments, email, domain/DNS).

    1.2k GitHub stars~13k tokensUpdated 3 days ago
    Backend & APIsAuto-check: notes
  • Wrangler

    hodgef/apiker

    Cloudflare Workers CLI for deploying, developing, and managing Workers, KV, R2, D1, Vectorize, Hyperdrive, Workers AI, Containers, Queues, Workflows, Pipelines, and Secrets Store.

    127 GitHub starsUsed in 5 repos~4.6k tokens
    Backend & APIsAuto-check passed
  • Cloudflare One

    hodgef/apiker

    Guides Cloudflare One Zero Trust and SASE work across Access, Gateway, WARP, Tunnel, Cloudflare WAN, DLP, CASB, device posture, and identity.

    127 GitHub starsUsed in 2 repos~5.6k tokens
    Backend & APIsAuto-check passed
  • Nest Devices

    sundial-org/awesome-openclaw-skills

    Control Nest smart home devices (thermostat, cameras, doorbell) via the Device Access API.

    663 GitHub stars~2.3k tokensUpdated 7 mo ago
    Backend & APIsAuto-check: notes
  • Cloudflare

    ericrisco/rsc-harness

    A skill your agent uses when working on Cloudflare's edge platform — wrangler.jsonc bindings, choosing between D1/KV/R2/Durable Objects/Queues, deploying a Worker or SPA via Static Assets, or…

    156 GitHub stars~2.6k tokensUpdated today
    Backend & APIsAuto-check passed
  • Tanstack Start

    Mindrally/skills

    Best practices for TanStack Start, the full-stack React framework built on TanStack Router and Vite/Nitro.

    267 GitHub stars~2k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed

More from sickn33/agentic-awesome-skills

All 1,394 skills in this repo
  • Liuguang Banlan UI

    sickn33/agentic-awesome-skills

    Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • User Thoughts Memory

    sickn33/agentic-awesome-skills

    Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Using LWC Memory and Graphs

    sickn33/agentic-awesome-skills

    Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.

    47k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Find Complementary Founders

    sickn33/agentic-awesome-skills

    Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.

    47k GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Whatsapp Cloud API

    sickn33/agentic-awesome-skills

    Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~4.5k tokens
    Auto-check passed
  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed

Works with

Questions about Zero Trust

What does Zero Trust do?

Implement zero-trust network architecture. An agent skill from sickn33/agentic-awesome-skills. Zero Trust is an agent skill from sickn33/agentic-awesome-skills. Implement zero-trust network architecture.

When should I use Zero Trust?

Zero Trust fits situations like: implementing modern security architectures.

How do I install Zero Trust in Claude Code?

Run `npx skills add sickn33/agentic-awesome-skills --skill zero-trust -a claude-code`. Or copy the skill folder (skills/zero-trust in sickn33/agentic-awesome-skills) into .claude/skills/zero-trust in your project. Claude Code loads it when a task matches its description.

How do I install Zero Trust in Codex?

Run `npx skills add sickn33/agentic-awesome-skills --skill zero-trust -a codex`. Or copy the skill folder (skills/zero-trust in sickn33/agentic-awesome-skills) into .agents/skills/zero-trust in your project. Codex loads it when a task matches its description.

Can I use Zero Trust in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill zero-trust -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/zero-trust, .gemini/skills/zero-trust, .github/skills/zero-trust and .opencode/skills/zero-trust in your project.

What does Zero Trust need to run?

Going by SKILL.md and its folder, Zero Trust needs the command-line tools its instructions call (curl and kubectl) and credentials named CF_TOKEN, CLIENT_SECRET and COOKIE_SECRET. Our summary lists: A credential in CLIENT_SECRET; A credential in COOKIE_SECRET. Compatibility (from SKILL.md): Requires the relevant security tooling (scanners, vault CLIs) and an authorized scope for any active assessment. Docs-only; helper scripts and templates not bundled..

Does Zero Trust access the network?

SKILL.md names 4 domains. In commands or code: api.cloudflare.com, accounts.google.com and internal-service.default.svc; the agent is likely to contact these when it follows the instructions. As links in the text: github.com. This is read from the text; nothing was executed.

Is Zero Trust safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Zero Trust use?

Zero Trust is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Zero Trust use?

About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Zero Trust?

Skills that share tags, products or a category with Zero Trust: Golive (mikehasa/golive-skill, 1.2k stars), Wrangler (hodgef/apiker, 127 stars), Cloudflare One (hodgef/apiker, 127 stars) and Nest Devices (sundial-org/awesome-openclaw-skills, 663 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Zero Trust?

sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,304 GitHub stars. The repository holds 1,394 skills in this directory. The repository was last updated on October 6, 2026.

Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.