Skip to content
Back to skills

Security Boundaries

ASecurity

Use when code executes commands, installs hooks/plugins, handles untrusted input, writes outside a workspace, or crosses privilege/network boundaries.

  • 5 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 3, 2026
ai-agentsrustshellsecurity

Security analysis

A100/100

Scanned September 3, 2026

npx -y skills add ShugokiFable/Ultimate-AI-Starter-Bundle --skill security-boundaries --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Security Boundaries?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Security Boundaries
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/shugokifable-security-boundaries/badge)](https://www.skillsdirectory.com/skills/shugokifable-security-boundaries)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: security-boundaries
description: Use when code executes commands, installs hooks/plugins, handles untrusted input, writes outside a workspace, or crosses privilege/network boundaries.
---

# Security Boundaries

## Core rule
Identify each **trust boundary** explicitly and apply **least privilege** at that boundary.

## Contract
Treat downloaded content, repository files from unknown origins, generated shell text, archive members, plugin hooks, environment variables, and user-supplied paths as **untrusted** until validated for the operation being performed.

Prefer argument arrays over shell interpolation; validate archive paths; constrain write roots; avoid privilege elevation unless required; verify signatures/hashes for bootstrapped executables when feasible; preserve provider trust prompts unless the user has explicitly opted into the exact automation being installed.

Do not disable dangerous-command approval globally to remove one setup prompt. Scope consent to the known component or one installer process.

Security checks are part of correctness: a “working” installer that can overwrite arbitrary paths or silently trust future third-party hooks is not near-perfect.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…