agents-security
v1.0.0agents-security is an Agent Plugin published by skillshop-ostyles. It packages 21 skills. We fetched the plugin.json from GitHub on 2026-10-05 and checked it against the official Agent Plugins 1.0.0 schema.
Security analysis skills: trust boundaries, secrets, authorization, input validation.
- Skills
- 21
- MCP servers
- 0
- Stars
- 0
- License
- MIT
- Repo created
- 2026-07-22
- Last pushed
- 2026-08-22
- Publisher type
- User
- Version
- 1.0.0
Links
Skills · 21
- api-contract-guardian
- API contract guard: extracts the API surface (HTTP routes with params, DTO fields, exported signatures, preferring OpenAPI files when present) from two git states of a repo, diffs them, classifies every change as breaking / non-breaking / additive, and writes a ready-to-ship consumer migration not…
- authorization-xray
- Authorization X-ray for your own codebase (defensive audit): inventories every HTTP endpoint and every recognizable protection layer (middleware chains, authorize decorators, inline role checks, router mounts), builds the permission matrix endpoint x required check, and reports unprotected mutating…
- authz-coverage-gap-detector
- Finds mutating endpoints that lack explicit authorization, relying solely on middleware inheritance, the dangerous gaps where middleware failure leaves endpoints unprotected. Read-only. Audience: Senior. Trigger: /authz-coverage
- config-cartographer
- Configuration cartographer: maps a system's complete config surface, every env var, setting and flag, where it is defined (.env, yaml/json configs, compose, Dockerfile) versus where it is read in code, and reports read-but-never-defined keys (crash candidates), defined-but-never-read orphans and…
- cors-config-drift
- CORS config drift scanner: harvests every Access-Control-Allow-Origin header, cors()-middleware call, @cross_origin decorator, options-handler with cors config, and per-route origin/credentials settings. LLM analyses each per-route CORS posture: credentials+wildcard = fatal, permissive origin patte…
- crypto-downgrade-detector
- Crypto downgrade detector: harvests every weak-algorithm usage (MD5, SHA1, DES, 3DES, RC4, ECB, CBC, deprecated createCipher), modern alternatives (subtle.encrypt, bcrypt, argon2, scrypt, PBKDF2), JWT signing-config (hardcoded-secret vs asymmetric key), cert/key-generation calls, and patch/version-…
- data-trail-tracker
- Maps PII fields and their sinks, logs, third-party APIs, exports, purely via field names, never via actual data. Trigger: /data-trail-tracker
- dep-inheritance
- Dependency inheritance audit: for every direct dependency answers the questions nobody asks, why is it here (from actual usage sites), how deep is the coupling, how replaceable is it, and what is the concrete exit plan. Parses manifests/lockfiles, scans usage, optionally enriches with registry met…
- error-message-leakage
- Error message leakage detector: harvests every HTTP-error-return and log-error-call, classifies what kind of information leaks (stacktrace, SQL error message, env-vars, user input echo, request dump). LLM validates each finding as legitimate production-leak and proposes sanitization. Read-only. Aud…
- flask-anti-pattern-detector
- Flask anti-pattern detector: scans Flask projects for hardcoded SECRET_KEY, debug-mode in production, dangerous template rendering (render_template_string), pickle/eval/exec on request data, unsafe session config, SQL injection via raw queries, insecure file upload, and debug toolbar enabled. LLM v…
- input-validation-audit
- Input validation audit: statically detects all input surfaces (HTTP params, CLI args, env vars, file reads, stdin) across a codebase, classifies their validation state (none/weak/adequate), and flags high-risk gaps. Produces an evidence-backed report with severity, location, and remediation suggest…
- log-injection-detector
- Log injection detector: harvests every console.log/logger.info/log.Error/etc call, classifies arguments for attacker-controlled input (CWE-117), CRLF injection surface, sensitive data leakage (passwords, tokens, secrets). LLM validates each finding as injectable and proposes sanitization (parameter…
- permission-chain
- rate-limit-shape-analyzer
- secret-lifecycle-auditor
- security-smell-scanner
- session-state-anomaly
- ssrf-detector
- third-party-trust
- tls-config-drift
- type-confusion-bypass-detector
Descriptions come from the frontmatter of each SKILL.md, punctuation lightly normalized.
Category
Security & Compliance. Assigned by this directory. Agent Plugins 1.0.0 has no category field, so no manifest declares one.
Keywords
agent-skills · security · secrets · authorization
Related by publisher and keywords
AI/ML pipeline skills: prompts, LLM costs, RAG, embeddings, guardrails.
Data layer skills: schemas, migrations, fixtures, and query patterns.
Operations and SRE skills: deployment, resilience, backups, CI health.
Code quality, smells, refactoring signals, and consistency skills.
Runtime analysis skills: performance, startup, concurrency, production parity.
Codebase understanding skills: architecture, onboarding, knowledge preservation.
[](https://agentpluginsdirectory.com/plugins/agents-security)✓ Verified . We fetched the manifest from GitHub and checked it against the official Agent Plugins 1.0.0 schema at agent-plugins.org.