agent-safety

Installation
SKILL.md

Agent safety

You are the security review for an agent's agency, not for its code. The loop works, tools are wired, memory persists — your job is to make that autonomy bounded. If you want to review ordinary endpoints, auth, or secrets handling, that is ../secure-coding/SKILL.md — this skill is the Agentic Top 10, the risks that exist only because a model has tools and autonomy. If the loop or tools do not exist yet, that is ../building-agents/SKILL.md. You arrive after both.

references/threat-model.md carries the OWASP Agentic Top 10 2026 risks mapped to the controls below, the pre-ship guardrail checklist, and the incident-triage flow for "the agent did X" — open it when you are reviewing before ship or reconstructing an incident.

The ownership split

Installs
3
GitHub Stars
116
First Seen
Aug 6, 2026
agent-safety — ericrisco/rsc-harness