Skip to content
Back to skills

Salt Code Policy Honesty Not Clone

ASecurity

Salt Code (getsaltcode.com by Salt Security) provides 40 security policies as prompt-time context injection, not an execution firewall. Steal the 40-policy taxonomy, OpenAPI query-string auth diode, and MCP credential hygiene onto ThumbGate PreToolUse rails. Never install Salt Code MCP or route traffic to mcp.getsaltcode.com. Slash: /salt-code-policy-honesty-not-clone.

  • 27 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 7, 2026
ai-agentsgoshellbashrailsapisecurity

Works with

  • cursor
  • api
  • mcp

Security analysis

A100/100

Scanned October 7, 2026

npx -y skills add IgorGanapolsky/ThumbGate --skill salt-code-policy-honesty-not-clone --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Salt Code Policy Honesty Not Clone?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Salt Code Policy Honesty Not Clone
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/igorganapolsky-salt-code-policy-honesty-not-clone-thumbgate/badge)](https://www.skillsdirectory.com/skills/igorganapolsky-salt-code-policy-honesty-not-clone-thumbgate)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: salt-code-policy-honesty-not-clone
description: >
  Salt Code (getsaltcode.com by Salt Security) provides 40 security policies as prompt-time
  context injection, not an execution firewall. Steal the 40-policy taxonomy, OpenAPI query-string
  auth diode, and MCP credential hygiene onto ThumbGate PreToolUse rails. Never install Salt Code MCP
  or route traffic to mcp.getsaltcode.com. Slash: /salt-code-policy-honesty-not-clone.
---

# Salt Code policy honesty — compare, do not clone

## Goal

Compare Salt Code's advisory prompt-time context injection against ThumbGate's deterministic execution-layer
PreToolUse firewall. Steal the 40-policy taxonomy (OWASP API Top 10, OWASP LLM Top 10, MCP Security, OpenAPI Hygiene)
and enforce fail-closed checks when security rules exist only in context without PreToolUse enforcement.

## Constraints

| NEVER | ALWAYS |
| --- | --- |
| Route MCP traffic to `mcp.getsaltcode.com` | Run 100% local stdio/subshell inspection |
| Rely on prompt-only rules (`.cursorrules`) to stop attacks | Enforce deterministic `PreToolUse` execution gates |
| Pass API keys or secrets in URL query parameters (`?apiKey=`) | Enforce `Authorization: Bearer` headers |
| Treat Salt Code as a drop-in substitute for ThumbGate | Distinguish advisory context from active execution firewall |

HARD fail closed. REFUSE SKU clones and cloud dependencies.

## Reference

- https://getsaltcode.com/ (Salt Security, 2026)
- `scripts/salt-code-policy-honesty.js`
- `docs/agents/salt-code-policy-honesty.md`
- ThumbGate Completion Claim Contract in `AGENTS.md` / `GEMINI.md`

## Examples (show, don't tell)

Weak: "Salt Code protects agents by giving them a system prompt with 40 rules."

Gold:
```bash
$ npx thumbgate salt-code-policy-honesty --inspect-context=.cursorrules --json
# Flags context_injection_without_pretool_enforcement if PreToolUse is unconfigured.

$ npx thumbgate salt-code-policy-honesty --map-only --json
# Dumps complete 40-policy taxonomy mapped to deterministic PreToolUse gates.
```

## Procedures

```bash
# Print taxonomy and rail map
npx thumbgate salt-code-policy-honesty --map-only --json

# Audit code, OpenAPI spec, and MCP config
npx thumbgate salt-code-policy-honesty \
  --inspect-code=src/api.js \
  --inspect-api=openapi/spec.yaml \
  --inspect-mcp=.mcp.json \
  --strict

# Run regression test suite
npm run test:salt-code-policy-honesty
```

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…