agent-tool-risk

Installation
SKILL.md

Agent Tool Risk

Use this skill for MCP, plugins, hooks, sub-agents, tool permissions, prompt flows, automation loops, and model-visible logs.

Workflow

  1. Inventory the agent/tool surface: trigger, command, permissions, inputs, outputs, and persistence.
  2. Classify risk:
    • prompt injection or untrusted content
    • excessive agency or destructive authority
    • secret exposure
    • data exfiltration through logs or MCP
    • command injection
    • stale or misleading model-visible memory
  3. Confirm high-risk operations have human approval or guard hooks.
  4. Ensure hidden logs are not loaded as default model context.
  5. Ensure model-visible logs contain only durable, necessary retry context.
  6. Update docs/harness/AGENT_SECURITY.md, docs/harness/SECURITY_POLICY.md, and docs/harness/SUBAGENT_PROTOCOL.md if behavior changes.
Installs
1
GitHub Stars
19
First Seen
11 days ago
agent-tool-risk — jh941213/codex-lattice