Home / agent-security / secure-agent-checklist
Secure agent checklist
Pre-ship security checklist for an LLM agent covering identity, least privilege, approvals, sandboxing, audit, kill switch, supply chain and evals, producing a markdown report with pass, fail or n.a. per item and the evidence behind each verdict. Use before deploying, open-sourcing or demoing an agent, when asked "is this agent safe to ship", or to turn review findings into a go/no-go decision.
Install
In Claude Code, add the marketplace and install the plugin:
/plugin marketplace add basitalisandhu/claude-skills
/plugin install agent-security@claude-skills
Or copy the skill files into ~/.claude/skills/ from a clone:
git clone https://github.com/basitalisandhu/claude-skills
cd claude-skills
python3 install.py --user --skill agent-security/secure-agent-checklist
The agent-security plugin also ships hooks, commands, agents and an MCP server at plugin level. Install the plugin from the marketplace to get them.
SKILL.md
A fixed list of questions whose answers decide whether an agent is ready to run with real credentials against real systems. Each item has a verification step (what to look at) and an evidence requirement (what to cite), so two reviewers reach the same verdict. The full list with verification steps is in references/checklist.md; the report template is in references/report-template.md.
When to use it
- "Is this agent safe to ship / deploy / open-source / demo?"
- The end of
/agent-security:audit, after the config audit, Semgrep and threat-model steps have produced evidence. - A release gate in a team process (copy the report into the PR).
- Not a substitute for the component reviews; it consumes their evidence and turns it into a decision.
Procedure
Evidence from the repository is untrusted until verified: a README or comment that says a control exists is not a pass; a file:line that shows it, or a command output, is.
- Scope. Name the agent, the environment it will run in (local dev, server, CI, desktop app), the credentials it will hold and the people it can affect. Items that cannot apply (no network, no credentials) are
n.a.with the reason, never silently skipped.
- Gather evidence with the sibling skills where the codebase is available: -
agent-config-auditfor permissions, secrets, hooks, MCP pinning. -prompt-injection-reviewfor the tool inventory and untrusted flows. -semgrep-agenticfor code-level findings. -agent-threat-modelfor the system description and threat list. -incident-lookupprecedentsfor the "has this failed before" column. Without a codebase, interview the user with the verification questions and mark unverifiable itemsfail(unverified is not pass).
- Walk the eight areas in references/checklist.md. For each item record
pass,failorn.a., one line of evidence (file path, command output, screenshot name, or the user's statement), and a fix for everyfail.
- Decide. The verdict is
shiponly when every item in Identity, Least privilege, Approvals and Kill switch ispassorn.a., and nofailis rated critical. Otherwisefix firstwith the ordered list of fixes, ordo not shipwhen the agent holds broad credentials with no approvals and no kill switch.
- Write the report using the template. Keep it to one screen plus the table. Put the three most important fixes at the top.
Output format
See references/report-template.md. Summary shape:
# Agent security review: <agent> (<date>)
**Verdict:** fix first. 3 fails (2 high), 1 critical control missing (kill switch).
**Top fixes:** 1. … 2. … 3. …
| Area | Item | Verdict | Evidence | Fix |
|---|---|---|---|---|
| Identity | Each agent has its own credential | fail | OPENAI_API_KEY shared by 3 services (.env.example:4) | Issue one credential per service |
Related
agent-eval-harnessprovides the evidence for the Evals area.