All skills
erkamyaman avatar

/agent-security-basics

@57c6daa

Use when letting AI agents run code, install packages or touch real systems. Covers sandboxing, least privilege and quarantine basics.

  • 2 files
  • 2.3 KB
  • Updated 15 hours ago
  • GitHub

Use this Skill: https://skilld.dev/gh/erkamyaman/dhh-p-bloom-agent-skills/agent-security-basics

This session only. Nothing lands on disk.

referenceschecklist.md

≈132 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Security checklist

  • Agent runs in a sandbox, not directly on a main machine
  • Only needed folders are mounted
  • No production secrets in the environment
  • Tokens are scoped and short-lived
  • Network access is limited to an allowlist
  • New dependencies are reviewed and versions pinned
  • Destructive actions need human approval
  • Web pages, issues and documents are treated as untrusted input
  • Commands and file changes are logged
  • Changes are reviewed before merging or deploying

Source: SKILL.md on GitHub

No third-party reports yet.

Signed by skilld at 57c6daa. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 9 hours ago.

Activeupdated 15 hours ago

README badge

README badge for erkamyaman/dhh-p-bloom-agent-skills/agent-security-basics