Agent Security Skills — Security skill for Claude Code
Claude Code security plugin and agentskills.io skill pack for securing LLM agents: threat modelling, config audits, prompt injection review, MCP server review, incident lookup, security evals, Semgrep.
How to install Agent Security Skills
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open basitalisandhu/agent-security-skills and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What Agent Security Skills does
Claude Code security plugin and agentskills.io skill pack for securing LLM agents: threat modelling, config audits, prompt injection review, MCP server review, incident lookup, security evals, Semgrep rules, guard hooks and an incident-database MCP server.
Alternatives in Security
- Security Threat Model — Generate repo-specific threat models identifying trust boundaries 14.6k ★
- Anthropic Cybersecurity Skills — 734+ structured cybersecurity skills for AI agents · MITRE ATT&CK mapped · agentskills.io open standard · Work 3.8k ★
- Trail Of Bits Claude-code-config — Opinionated production defaults from a top security firm: sandboxing, permissions, hooks, skills, MCP server c 1.6k ★
README
agent-security-skills
**Claude Code security plugin and agent skills for securing LLM agents: threat modelling, configuration audits, prompt injection review, MCP server review and incident lookup.**
agent-security-skills is a Claude Code plugin marketplace and an [agentskills.io](https://agentskills.io)-compatible skill pack for people who build or run LLM agents against real APIs, MCP servers and codebases: security engineers reviewing an agent before it ships, and developers who want that review inside the tool they already use. Each skill is a procedure with a tested script or a fixed checklist, so two reviewers reach the same verdict and the evidence is a file, a line or a command output.
Eight skills (each with a tested script or a checklist), three slash commands, a subagent, two guard hooks for `Bash`, and an optional MCP server over the [ai-agent-incidents](https://github.com/basitalisandhu/ai-agent-incidents) dataset (80 documented events mapped to OWASP Agentic, OWASP LLM and MITRE ATLAS). No telemetry, no network calls except the documented, opt-in dataset refresh.
When to use this
- How do I review an MCP server for security from inside Claude Code?
mcp-server-review - How do I threat-model an AI agent with a coding assistant?
/agent-security:threat-model - Is this agent vulnerable to prompt injection, and where do approvals and provenance checks belong?
prompt-injection-review - Which Claude Code hooks block dangerous tool calls, such as printing secrets or piping
curlinto a shell? The two bundledPreToolUsehooks - Is the
.claude/or.mcp.jsonin a repository I just cloned safe to open with an agent?agent-config-audit
Install
In a Claude Code session:
/plugin marketplace add basitalisandhu/agent-security-skills
/plugin install agent-security@agent-security-skills
From a shell (for scripts and CI machines):
claude plugin marketplace add basitalisandhu/agent-security-skills
claude plugin install ag
Related Skills
Security Audit Extended
Read-only security audit skill for coding agents. Cloudflare's audit workflow (coverage ledger, verdict contra
Cve MCP Server
Production-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS sco
Security AI Workflows
AI assistants can support security engineering through code analysis, threat identification, configuration rev
Openclaw Config Pack
Hardened configuration pack for OpenClaw personal AI assistant — 9-layer security, Telegram topics, plugins, s
Security Playbook
Security skill pack for AI coding agents — behavioral guardrails, OWASP code/LLM rules, static analysis guidan
Osint Agent Skills
OSINT knowledge base + MCP server for autonomous AI agents — Claude Code, Cursor, Kimi K3, recon & threat inte
Related Agents
Vuln Recon
Maps a target repository's attack surface, writes a threat model, plans hunt work units, and optionally writes
AI Data Specialist
Deep AI/data engineer — LLM integration and agent systems, RAG, evals, data pipelines, and ML productionizatio
ML Engineer
Use for ML/AI model work — training, fine-tuning, evaluation, RAG, agents, embeddings, evals, deployment, MLOp