All authors

Claude Skills by open-coder-ai
github.com/open-coder-ai93 skills0 installs51 views
- Owasp Asi05 Unexpected Code ExecutionContain code an agent generates or is induced to run. Execute in a sandboxed container with least privilege and deny-by-default egress, prefer parameterised APIs over raw shell, and treat any string reaching a subprocess or interpreter as attacker-controlled. Use when adding a code interpreter, shell tool, subprocess call, or eval-style API to an agent. Do NOT use for eval/exec appearing in ordinary application code \u2014 that is `code-safety`.Votes: 0GitHub stars: 3
- Owasp Asi06 Memory Context PoisoningStop untrusted content from being written into an agent's durable memory or retrieval index, where it silently steers behaviour in later sessions. Keep context ephemeral by default, validate and attribute every memory write, scope memory per user and per task, and let operators inspect and flush it. Use when adding long-term memory, a vector index, session summarisation, or user preference storage. Do NOT use for the coding agent's own memory files \u2014 that is `memory-discipline`.Votes: 0GitHub stars: 3
- Owasp Asi07 Insecure Inter Agent CommunicationAuthenticate and integrity-protect the channels agents use to talk to each other, so a peer cannot be impersonated, a message tampered with, or a fake agent registered in discovery. Use when building multi-agent orchestration, agent-to-agent protocols, delegation between agents, message buses, or agent discovery services. Do NOT use for a single agent calling ordinary tools \u2014 that is `owasp-asi02-tool-misuse`.Votes: 0GitHub stars: 3
- Owasp Asi08 Cascading FailuresKeep one agent's bad output from propagating through everything downstream. Isolate blast radius per agent and per environment, separate development from production access, validate agent-to-agent handoffs, and add circuit breakers that halt automation on behavioural deviation. Use when chaining agents, designing orchestration, granting production access, or wiring agent output into downstream automation. Do NOT use for the transport security of those handoffs \u2014 that is `owasp-asi07-inse...Votes: 0GitHub stars: 3
- Owasp Asi09 Human Agent TrustStop an agent from controlling the information a human approves against. Show the raw action rather than a model-authored summary at every confirmation step, forbid persuasive framing in sensitive workflows, and keep an immutable record of what was presented versus what executed. Use when designing approval prompts, human-in-the-loop checkpoints, agent-written PR descriptions, or consent and disclosure flows. Do NOT use for what the agent is permitted to do once approved \u2014 that is `owasp...Votes: 0GitHub stars: 3
- Owasp Asi10 Rogue AgentsMake an agent that has drifted, been compromised, or was never inventoried detectable and stoppable. Require an owner, expiry, and inventory entry for every agent, sandbox by default, baseline behaviour and alert on deviation, and keep a tested kill switch. Use when deploying a long-running or autonomous agent, allowing sub-agent spawning, or reviewing agent lifecycle and monitoring. Do NOT use for a single hijacked request within a supervised session \u2014 that is `owasp-asi01-agent-goal-hi...Votes: 0GitHub stars: 3
- Chock Misetrigger: personalize the coding agent to its owner -- adopt the owner's dialect, taste, habits and demeanor so it works like a trained twin of that developer. apply: the owner's chock-mise profile where present; defer to committed project standards where it is silent or conflicts. avoid: inferring personal identity or employer-confidential data, and overriding the project's own committed rules.Votes: 0GitHub stars: 3
- No A11y Regressiontrigger: remediating accessibility, editing markup, emptying or removing an alt, aria-label, label or lang that an element already had, deleting a flagged element. avoid: breaking a requirement the previous revision met; interrupting a correct fix.Votes: 0GitHub stars: 3
- Eu Ai Act High Risk TriageWarns when code puts an AI system into an EU AI Act Annex III high-risk domain \u2014 biometrics, critical infrastructure, education, employment, essential services and credit, law enforcement, migration, justice and elections \u2014 and asks for an owner of the Article 9-15 obligations before the capability ships. Use when adding scoring, ranking, eligibility, or screening over people. Do NOT use for banned practices (see eu-ai-act-prohibited-practices) or for systems with no natural-person ...Votes: 0GitHub stars: 3
- Eu Ai Act Prohibited PracticesAdvisory rule that tells the agent to decline AI practices banned outright by EU AI Act Article 5: social scoring, untargeted facial-image scraping, emotion inference at work or school, biometric categorisation by sensitive traits, profiling-only predictive policing, subliminal or vulnerability-based manipulation, real-time remote biometric ID in public spaces, and NCII/CSAM generators. Use when a feature request names any of these. Do NOT use for lawful biometric verification, fraud detectio...Votes: 0GitHub stars: 3
- Eu Ai Act TransparencyKeep EU AI Act Article 50 duties in the code: disclose to a person that they are interacting with an AI system, mark generated audio, image, video, and text in a machine-readable format, and label deepfakes. Use when adding a chatbot or assistant surface, a generation endpoint, or an export path for model output. Do NOT use for assistive editing that does not substantially alter the input, or for internal batch jobs with no human recipient.Votes: 0GitHub stars: 3
- Protect Commit PrivacyKeeps the development conversation out of git history. Guard refuses `git commit` and `gh pr create|edit` whose message or body (inline -m/-b, -F/--file/--body-file, heredoc on -F -) holds a process-leak marker (session link, 'user asked', ...); commands behind cd, sh -c, sudo, env are read. A commit-msg hook applies the same markers to the recorded message. Narrow deny-list. No waiver: a legitimate phrase needs a person to remove it from MARKERS in the guard; an agent asks the person.Votes: 0GitHub stars: 3
- Java Securitytrigger: writing Java or Kotlin (Spring, Jakarta EE, Quarkus, Android), SQL/JPA/MyBatis, templates, application.properties/.yml, web.xml, pom.xml, Gradle; \"customize java security\" opens the guided page. avoid: injection, XXE, SSRF, unsafe deserialization, path traversal, weak crypto, trust-all TLS, Spring Security off, exposed secrets, known-exploited deps, SpotBugs/Sonar/PMD/Checkstyle findings. 129 rules, 16 packs, each allow|deny|ask in .chock/security.json; absent = deny (quality: allow).Votes: 0GitHub stars: 3
- Rtk Dangerous Actions BlockerDeprecated: use block-destructive-commands, which shares this policy's destructive-command table. rtk#1007. Destructive verdicts come from the chock_destructive table shared with block- destructive-commands: the same blocks (root/home deletes, force/delete/mirror pushes, reset --hard, clean -f, IaC destroy, cloud deletes, DB drops, lockouts) and asks (rm -rf off rtk's safe list, bare lease, stash drop, prunes, -auto-approve). Own rows block credential-file reads (.env, keys, ~/.ssh) and echo ...Votes: 0GitHub stars: 3
- Agentic Code Securitytrigger: writing agent code or agent config -- Python or TypeScript using AutoGen, CrewAI, LangChain, LangGraph, mem0, the OpenAI Agents or Claude Agent SDK, an MCP server or client (.mcp.json, .cursor/mcp.json, .vscode/mcp.json, claude_desktop_config.json, .codex/config.toml, .gemini/settings.json), docker-compose files for agents. avoid: code execution on the host, unpinned MCP servers and models, shell-reaching tools, approvals switched off, whole-environment and credential-store leaks, TL...Votes: 0GitHub stars: 3
- Block Test SkipsBlocks newly added test skips, focus markers and runner options that hide tests: pytest/unittest skips, non-strict xfail, importorskip; JS skip/only/todo/fixme, x/f prefixes; JUnit Disabled/Assume; Go Skip, Short(); Rust ignore; RSpec, PHPUnit, C#, Swift skips; --deselect/-k not, collect_ignore, jest testPathIgnorePatterns. Runs: commit, agent write, turn's end; only additions judged. Friction: computed names evade it. Waiver: 'chock: allow test-skip' same line; agent: only if in HEAD.Votes: 0GitHub stars: 3
- Block Unguarded Agent SpawnBest-effort guard against launching a coding agent with safety checks off: claude --dangerously-skip-permissions, bypassPermissions or a wildcard --allowedTools; codex --full-auto, --yolo, --ask-for-approval never, danger-full-access; gemini --yolo or --approval-mode yolo; cursor-agent --force; aider --yes-always; copilot --allow-all-tools; amp, cline, goose, opencode auto-approve. Looks through cd, bash -c, sudo, env, npx, uvx. Misses: config, aliases, scripts, ssh.Votes: 0GitHub stars: 3
- Guard Memory WritesRefuses agent-memory writes holding pasted git history, a code block over 20 lines, a duplicate line or a secret. Warns (observe, ASI06) on an added line that tells the agent to run a command or fetch a URL, an encoded blob, and, only where the repo keeps .chock/egress-allowlist.txt, a URL host off it. Judges memory files only (MEMORY.md, CLAUDE.local.md, .claude/memory/**, memory/**/*.md, the agent's own stores) and what a change adds. No waiver. A write after an untrusted fetch is not seen.Votes: 0GitHub stars: 3
- Limit Diff Sizetrigger: staging a large change, committing more than a reviewer can read at once. avoid: one commit carrying hundreds of hand-written lines; lockfile and generated churn is not counted.Votes: 0GitHub stars: 3
- Protect Test IntegrityBlocks weakening tests to turn them green: a deleted test file (commit only), a net loss of assertions, or an added vacuous assertion (assert True, expect(true).toBe(true)). Added skips are block-test-skips. Runs: commit (incl. an agent's commit: CHOCK_AGENT_COMMIT, CLAUDECODE=1, AI_AGENT or agent_commit_env), agent write (vs disk), turn's end (vs HEAD). Waiver: 'chock: allow test-integrity' on an added line. Person's commit: honoured. Agent: only if already in HEAD; it asks a person.Votes: 0GitHub stars: 3
- Agent Devenv AutoexecWarns only (observe): flags files that make a dev tool run code on open, clone or shell entry -- agent hooks, helpers, env/BASE_URL overrides, auto-approve; VS Code folderOpen tasks, trust off, repo executables; devcontainer initializeCommand; .envrc, mise, husky, lefthook, pre-commit; gitconfig exec keys, gitattributes drivers, unsafe .gitmodules. Commit, agent write, turn's end; additions only; unreadable configs refused. Friction: misses interpreted code and unlisted files.Votes: 0GitHub stars: 3
- Block Hook Bypass In FilesFriction, not a security boundary: flags lines added to hook launchers and scripts that switch git hooks off -- the hook-skip option on a git commit/push/merge/am/rebase/pull, core.hooksPath set by git config or GIT_CONFIG_*, the husky, lefthook and pre-commit off-switch variables, a pre-commit, lefthook or husky (v8 and older) uninstall -- in .husky/, .githooks/, lefthook, package.json, Makefile, justfile, .envrc, *.sh. Blocks. Misses: split lines, -n.Votes: 0GitHub stars: 3
- Ci Github Actions SecurityFriction, not a security boundary: refuses or asks (each rule's tier) on GitHub Actions weaknesses a change adds to workflows, composite actions and dependabot.yml: event text in run/script, PR-head checkout under pull_request_target/workflow_run/issue_comment, missing or write-all permissions, secrets inherit or inlined, self-hosted runners on PRs, GITHUB_ENV writes, artifact and cache poisoning, agent steps on untrusted text. Misses: step outputs, composite internals, custom runner labels.Votes: 0GitHub stars: 3
- Dockerfile Compose SecurityBlocks (some rules ask) when a change to a Dockerfile, Containerfile or compose file adds: a base image with no tag, latest, an unresolvable ARG or no digest (stage-aware: FROM or COPY --from a stage is not an image); a final stage running as root; TLS or package-signature checks off; secret-named ENV/ARG/environment literals; COPY of key or .env files; remote ADD without checksum; fetch piped to a shell; RUN --security=insecure; chmod 777 or setuid; sudo, sshd, chpasswd; unpinned git clone; ...Votes: 0GitHub stars: 3
- Lockfile IntegrityScript gate (commit, agent write, CI) over npm, yarn, pnpm, bun, poetry, uv, Pipfile, Cargo, go.sum, Gemfile, composer and NuGet locks. Blocks: source off the registry list or not https, missing hash, hash changed for a locked version, unpinned git source, unreadable lock. Asks: SHA-1-only hash, transitive install script, lock or manifest moved alone, go.sum lines removed, lock ignored or deleted. Judges what a change adds. Friction, not a security boundary.Votes: 0GitHub stars: 3
- Package Lifecycle ScriptsBlocks fetch-exec class hooks and asks about other new ones when a change adds or edits code that runs at install or build time: npm install/prepare/pack scripts, gypfile without native sources, bin shadowing, unpinned git/URL deps; setup.py cmdclass and import-time calls, .pth imports, conftest, pyproject build hooks; build.rs and build-deps; go:generate; MSBuild Exec; gemspec, extconf, Podfile, Composer, Maven, Gradle exec. Judges file text, not what a hook runs. Friction, not a security bo...Votes: 0GitHub stars: 3
- Review Like A Red Teamtrigger: finishing or committing a diff that touches code, build or CI config, dependencies or agent config; a plan adding a handler, parser, auth path, crypto or sink; an ask-tier gate finding. Self-review of the diff in twelve red-team techniques, triaged by references/triage.json, reported as findings with exploit scenarios. Advisory: refuses nothing, writes no waiver, lowers no gate.Votes: 0GitHub stars: 3
- Scan Suppression MarkersAsks a person before a change adds a scanner suppression: inline ignore markers (bandit, gosec, ruff S codes, Sonar, Semgrep, ESLint security, Checkov, tfsec, Trivy, KICS, hadolint, cfn_nag, zizmor, gitleaks, detect-secrets, CodeQL, Java/C#/Rust security allows), scanner ignore files and skip keys, a CI scan set to pass on failure. Only added lines; prose skipped. Runs: commit, agent write, turn's end; CI annotates. Line-local, friction not a boundary.Votes: 0GitHub stars: 3
- Iam Policy ScanReads whole IAM, RBAC and role documents, not lines: JSON, YAML, Terraform, ARM, Bicep, Kubernetes. Refuses Allow with Action star or an inverted key, public or any-principal trust, cluster-admin, subscription Owner. Asks for service wildcards on a named resource, cross-account trust. Only added grants. Misses computed grants, partial wildcards, GCP, Azure role definitions, k8s escalate/bind/anonymous, unlisted extensions. Waiver: pragma or sidecar.Votes: 0GitHub stars: 3
- Agent Permissions ScanBlocks: parses agent permission configs (.claude/settings*, .codex, .gemini, .vscode, .cursor/cli.json, opencode, .aider, .continue) and flags added bare or wildcard allows (Bash, curl/rm/sudo/git push, WebFetch, Write/Edit globs, mcp__*), removed deny entries, bypass/auto modes, codex never+danger, yolo, autoAccept, yes-always, regex-all VS Code approve. Misses: MCP configs, scripts, Read.Votes: 0GitHub stars: 3
- Block Persistence ShapesBest-effort guard against shell commands that publish or keep access after the session: npm/pnpm/yarn/twine/ poetry/uv/cargo/gem publish, docker/podman push and login, npm token and registry edits, repos made public; user services, launch agents, cron/at/schtasks, Run keys, authorized_keys, runner registration, sudoers, setuid bits, detached downloads. Asks on gh release create, git remote add, git push to a URL. Misses: scripts, aliases, system units, shell rc files, ssh-run commands.Votes: 0GitHub stars: 3
- Block Secret Store ReadsBest-effort guard against an agent reading credentials from the shell: cat, grep, sed, cp, tar, base64, source or < on ~/.ssh (not .pub), ~/.aws, ~/.npmrc, ~/.netrc, ~/.kube, ~/.gnupg, agent CLI dirs, browser login DBs, wallets, .env (not .env.example), *.tfstate; interpreter one-liners naming them; gh auth token, aws sts get-session-token, git credential fill. Asks on env/printenv dumps. Misses: scripts, unresolved variables, xargs lists, $(...) results.Votes: 0GitHub stars: 3
- Compromised Package IocBlocks adding a known-malicious package version (npm, PyPI, crates, Go, RubyGems, Packagist manifests and lockfiles), a re-pointed action ref, or an IOC file name, from a dated, sourced list (data/ioc.json, CI fails 120 days after as_of). Runs: commit, agent write, turn's end; only additions judged. Exact versions only: a range is not resolved. A snapshot, not a feed; friction, not a boundary. Adopt under rollout observe.Votes: 0GitHub stars: 3
- Guard Deletiontrigger: a change that removes a check, auth decorator, middleware registration, sanitizer call or path check with none of its kind in the same hunk (ask), or removes a hardening flag, security header, cookie attribute, TLS check or row-level security, or swaps one of those or a narrow file mode for a weakened form (block). Hunk-local: misses a guard moved across hunks or files, one neutralised in place, added insecure settings, a deletion-only commit.Votes: 0GitHub stars: 3
- Hardening FlagsBlocks added settings that weaken compiler, linker, Rust or kernel hardening, in CMake, Make, meson, configure.ac, Cargo, build.rs, Go release scripts, Dockerfiles and kernel config: no stack protector, FORTIFY_SOURCE off, non-PIE, execstack, norelro, CET off, kernel KASLR/RWX off. Asks on Rust release overflow-checks off, /dev/mem. Not MSVC, sysctl or container settings; misses environment flags, generated files. Runs: commit, agent write, turn's end, CI. Waiver: 'pragma: allowlist hardening...Votes: 0GitHub stars: 3
- Opaque Blob GuardWarns (observe rollout; never refuses yet) when a change adds or edits, in tests/, fixtures/, testdata/, spec/, m4/, vendor/, gradle/wrapper/: a file whose first bytes are an archive, executable, wasm or database signature (any extension), a random-looking non-media file over 100 KB, or a symlink out of the repo; m4/configure/Makefile text that decodes and evaluates; a gradle wrapper jar changed with no new distributionSha256Sum. Misses text-encoded or prefixed payloads, other folders.Votes: 0GitHub stars: 3
- Refname Filename MetacharRefuses names a shell, CI step or git can misread. Paths a change adds or renames into (commit, agent writes), and branches and tags pushed (pre-push), with command substitution, an IFS expansion, a backtick, ; & | < >, a control or bidi character, a base64-decode shape, a leading dash or trailing space or dot in a segment, or a '..' segment; a ref also with a full commit id's shape. A guard refuses git and file commands creating such names. No waiver. Friction, not a boundary.Votes: 0GitHub stars: 3
- Scan Hidden ContentWarns (observe) when a change adds text a reader cannot see, or a URL that carries data out, to Markdown, HTML, SVG, XML, Word, agent instruction files, docs and templates: instruction-like or long comments, CSS-hidden, white or 1pt text, hidden Word runs, URLs with secret words, long queries, placeholders or encoded parts, remote embeds, camo runs, HTML data URIs. Runs: commit, agent write, turn's end. Waiver: a person's marker comment line above. Friction, not a boundary.Votes: 0GitHub stars: 3
- Scan Instruction FilesAsks a person before a change adds injection text to an agent instruction file (AGENTS.md, CLAUDE.md, GEMINI.md, Cursor/Windsurf/Cline/Roo/Kiro rules, Copilot instructions and prompts, SKILL.md, agent commands): rule overrides, secrecy, auto-approve, hook or review bypass, fetch-and-run, remote instructions, role swaps, fake system tags, removed guardrails. Refuses secret exfiltration and encoded payloads. Added text only; English phrases; friction, not a boundary.Votes: 0GitHub stars: 3
- Scan Secret FilesFriction, not a security boundary: flags files that are secrets by name or content -- private keys and key stores, Google service-account/OAuth JSON, kubeconfig users, AWS, npm, PyPI, netrc, git, pgpass, docker, Composer, NuGet, Maven credentials, tfstate/tfvars, non-template .env, framework secret files, browser stores. Blocks; encrypted keys, notebook outputs and test, fixture, example, doc, lock and eval paths ask. Misses: renamed binary stores other than PKCS#12/JKS/DER, unlisted secret n...Votes: 0GitHub stars: 3
- Block Fetch Exec In FilesWarns (observe rollout) when a line added to a script, Dockerfile, Makefile, CI workflow or package.json wires a download into a code runner: curl/wget/aria2c/lynx/iwr/irm piped into a shell, python/perl/ruby/node/php/lua on stdin, pwsh or iex; bash -c, eval, source or a here-string of a $(...) or <(...) download; Dockerfile ADD of a URL without --checksum. One line at a time: continuation lines, variables, unicode-escaped JSON, split or quoted command names, a download saved to a file and ru...Votes: 0GitHub stars: 3
- Registry ConfigRefuses package-manager config that redirects installs or weakens them: literal tokens, http or unlisted registry hosts (parsed, so lookalike and userinfo spellings fail), TLS or checksum checks off, install scripts on (npm, Yarn, pnpm, Bun, pip, uv, Poetry, conda, Go, Cargo, NuGet, Maven, Bundler, Composer, Hex, Dependabot); asks on extra indexes, replaces, no cooldown. Added only. Ship observe first. Friction, not a boundary.Votes: 0GitHub stars: 3
- Scan Secrets EntropyFriction, not a security boundary: asks a person before a write adds secrets scan-secrets misses -- high-entropy values (16-150 chars) by secret-like keys, GitHub/npm tokens with valid checksums, Stripe test keys, Slack/AWS key-id shapes, Luhn-valid cards. Asks a person (HP01 entropy is a heuristic, so it asks rather than blocks). Misses: values split across lines, over 150 chars, cut by # or & when unquoted, under other key names, written like code (a.b(), ALL_CAPS, words, URLs, paths), wrap...Votes: 0GitHub stars: 3