askalf

Agent Security Stack — Security skill for Claude Code

Security community

The open-source agent-security stack — redstamp + truecopy + strongroom — composed into one layered defense.

How to install Agent Security Stack

This entry records only its repository, not the path inside it, so there is no exact command to give. Open askalf/agent-security-stack and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

What Agent Security Stack does

The open-source agent-security stack — redstamp + truecopy + strongroom — composed into one layered defense. Vet the tool, contain the call, give it a key it never holds. Related: plumbline, the out-of-band trajectory monitor. Part of Own Your Stack.

Alternatives in Security

  • Defense In Depth — Implement multi-layered testing and security best practices 98.1k ★
  • Azure Key Vault .net — Cryptographic key management 1.8k ★
  • Memory Self Review — Mine recent agent history (claude-mem + usage stats) for recurring failures and repeated patterns, audit MEMOR 297 ★

README

agent-security-stack

[![CI](https://github.com/askalf/agent-security-stack/actions/workflows/ci.yml/badge.svg)](https://github.com/askalf/agent-security-stack/actions/workflows/ci.yml) [![CodeQL](https://github.com/askalf/agent-security-stack/actions/workflows/codeql.yml/badge.svg)](https://github.com/askalf/agent-security-stack/actions/workflows/codeql.yml) [![Fuzzing](https://github.com/askalf/agent-security-stack/actions/workflows/cflite.yml/badge.svg)](https://github.com/askalf/agent-security-stack/actions/workflows/cflite.yml) [![OpenSSF Scorecard](https://api.scorecard.dev/projects/github.com/askalf/agent-security-stack/badge)](https://scorecard.dev/viewer/?uri=github.com/askalf/agent-security-stack)

_**Own your agent security.**_ The open-source agent-security suite — **[redstamp](https://github.com/askalf/redstamp) · [truecopy](https://github.com/askalf/truecopy) · [strongroom](https://github.com/askalf/strongroom)** — three tools that compose into one layered defense for every agent tool call, exposed as one MCP server. Part of **[Own Your Stack](https://github.com/askalf)**.

OpenClaw became 2026's first big AI-security disaster three ways at once: one-click **RCE**, a **poisoned skills** marketplace, and ~135k **leaked credentials**. Three failure modes — three small, open-source, zero-dependency tools, composed into one layered defense:

| | own your… | closes | role | |--