Muhammad Basit Ali

I am Muhammad Basit Ali, a cloud security and AI agent security engineer. My day-to-day work is cloud governance: multi-account AWS guardrails, identity and endpoint controls in Microsoft 365, access reviews and the engineering teams that run them. Before that I built backend systems in Python and TypeScript, including a regulated lending platform and real-time grid software. The repositories here are the open part of that work: Claude Code skill packs, MCP servers and linters, threat modelling and static analysis for agent code, and a dataset of AI agent incidents. Each one stands alone, says what it does not do, and backs its security claims with tests.

Projects

Claude Code skill packs

RepositoryWhat it is
claude-skillsEvery skill I maintain, in one repository: 87 skills in 13 plugins from the packs below, one marketplace, one install script, synced daily.
aws-security-skillsAWS security skills for Claude Code: account audit, SCP guardrails, blast-radius landing zones, IAM least privilege, Security Hub triage.
repo-engineering-skillsRepository engineering skills for Claude Code: docs checked against the code, audits where every finding cites a line, agent context files that say only what code cannot.
m365-governance-skillsMicrosoft 365 governance skills for Claude Code: Entra ID posture review, Intune baseline check, Graph permission preflight, Teams and group sprawl, access review pack.
compliance-evidence-skillsCompliance evidence skills for Claude Code: integrity-checked evidence packs from GitHub, AWS and Microsoft 365 exports, mapped to ISO 27001 and SOC 2, with narratives that cite evidence or say not assessable.
claude-dev-skillsClaude Code skills for everyday development: code review, refactoring, debugging, CI and containers, data and APIs, documentation and security basics.
agent-security-skillsClaude Code security plugin and agent skills for securing LLM agents: threat modelling, configuration audits, prompt injection review, MCP server review, incident lookup.
github-manager-skillsClaude Code skills for engineering managers that compute from exported GitHub data: stuck-PR and review-queue digest, iteration report, blameless postmortem timeline.
mac-maintenance-skillsClaude Code skills for cleaning up and speeding up a Mac: read-only survey first, safe tier removes only what programs recreate, leftovers and duplicate finders.

MCP tooling

RepositoryWhat it is
dev-mcp-serversTen small MCP servers for everyday development and security checks.
mcp-server-templateSecure MCP server template in TypeScript and Python, safe by default.
mcp-tools-lintLint MCP tool schemas and annotations before clients reject them.
mcp-auth-doctorDiagnose OAuth discovery problems on remote MCP servers.
mcp-egressRecord every host an MCP server contacts, per tool, and fail CI on new ones.
claude-mcp-allowLeast-privilege Claude Code permission rules for MCP tools, generated from their annotations.
agentdojo-mcpRun AgentDojo against MCP servers.
mcp-rc-checkMCP specification migration checker for the 2026-07-28 revision.

Security tooling

RepositoryWhat it is
agent-threat-modelThreat modeling for AI agents: describe the system in YAML, get a STRIDE and OWASP Agentic threat model.
agent-config-auditAudit AI agent configuration files for security risks.
agentic-semgrep-rulesSemgrep rules for AI agent code in Python, TypeScript and JavaScript.
security-actionsGitHub Actions for AI agent and supply chain security checks.
cc-hooksTyped Python SDK and offline test runner for Claude Code hooks.
cc-plugin-lockLock file for Claude Code plugins: pins plugins and skills to content hashes and verifies them before load.
claude-perm-simClaude Code permission rule simulator: shows which rule decides a tool call and where a rule set is permissive.
llms-txt-genGenerate llms.txt for any docs site or repository.
scp-guardrailsAWS service control policy builder and linter.
skill-scan-gateCI gate for Claude Code skills and plugins.
spotlightingSpotlighting for prompt injection defence in Python.

Data and lists

RepositoryWhat it is
ai-agent-incidentsAn open dataset of AI agent and LLM security incidents, with a browsable site.
awesome-agent-securityCurated list of AI agent security tools, papers and datasets.

Latest releases

ProjectReleasePublished
spotlightingv0.1.0
skill-scan-gatev0.1.0
security-actionsv0.1.0
scp-guardrailsv0.1.0
repo-engineering-skillsv0.3.0
mcp-tools-lintv0.1.0
mcp-server-templatev0.1.0
mcp-rc-checkv0.2.0

Packages: container images and npm packages are listed on the Packages tab.

Posts