Home / agent-security

Agent Security

Security skills for LLM agents: threat model a codebase, audit agent configuration, review MCP servers, trace prompt injection to tool calls, look up incident precedents, run security evals, and scan with Semgrep. Includes guard hooks for Bash and an optional incident-database MCP server.

Plugin agent-security, version 0.1.1, 8 skills, MIT licence. Source: agent-security-skills. Synced .

Install

In Claude Code, add the marketplace and install the plugin:

/plugin marketplace add basitalisandhu/claude-skills
/plugin install agent-security@claude-skills

Or copy the skill files into ~/.claude/skills/ from a clone:

git clone https://github.com/basitalisandhu/claude-skills
cd claude-skills
python3 install.py --user --only agent-security

This plugin also ships plugin-level hooks, commands, agents and an MCP server. They load when you install the plugin from the marketplace; install.py copies skills only.

Skills

SkillWhat it doesScripts
agent-config-auditAudit AI-agent configuration for risky permissions, leaked secrets, unpinned MCP servers and prompt-injection in instruction files.yes
agent-eval-harnessSet up AgentDojo-style security evaluations for an agent: benign user tasks, injection tasks planted in tool results, utility and attack-success-rate metrics, and a policy hook (provenance, approval) in the tool executor.yes
agent-threat-modelWrite a system description of an LLM-agent codebase in the agent-threat-model YAML format (principals, agents, channels, tools, data stores, controls), validate it with atm validate, run atm analyse for a STRIDE and OWASP threat model with residual risk scoring, then interpret and summarise the result with incident precedents.yes
incident-lookupLook up real AI agent security incidents, vulnerability disclosures and threat reports (80 coded events, 2023 to 2026, mapped to OWASP Agentic Top 10, OWASP LLM Top 10 and MITRE ATLAS) and summarise precedents for a design.yes
mcp-server-reviewChecklist-driven security review of an MCP server implementation (TypeScript or Python) covering authentication, transport binding and origin checks, input validation, tool description poisoning, resource and path handling, SSRF, rate limits and secret-free logging, with a Semgrep pass.no
prompt-injection-reviewTrace untrusted inputs (web pages, emails, documents, tickets, repo issues, tool results, retrieved memory) to consequential tool calls in an agent codebase and judge each flow with deterministic provenance and approval rules.yes
secure-agent-checklistPre-ship security checklist for an LLM agent covering identity, least privilege, approvals, sandboxing, audit, kill switch, supply chain and evals, producing a markdown report with pass, fail or n.a. per item and the evidence behind each verdict.no
semgrep-agenticRun the agentic-semgrep-rules pack (36 rules for Python, JavaScript and TypeScript agent code: model output reaching exec, shells, SQL, URLs, file paths and HTML; user input in system prompts; tool parameters reaching shells and paths; MCP servers without auth or bound to every interface; leaked provider keys; unsafe model and config loading) against a repository, fall back to the bundled offline rules, and triage the results.no