Aegis AI Agent Security — Security skill for Claude Code
Enterprise AI-coding-agent security: a lightweight endpoint agent governs Cursor, Claude Code, Codex, Windsurf, Gemini CLI, GitHub Copilot, QwenWork, Tongyi Lingma, CodeBuddy, WorkBuddy and more; scan.
How to install Aegis AI Agent Security
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open yjiod/aegis-ai-agent-security and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What Aegis AI Agent Security does
Enterprise AI-coding-agent security: a lightweight endpoint agent governs Cursor, Claude Code, Codex, Windsurf, Gemini CLI, GitHub Copilot, QwenWork, Tongyi Lingma, CodeBuddy, WorkBuddy and more; scans Skill/MCP/code/dependency/secret risks; signed policy enforcement, zero-touch auto-enrollment, native macOS/Windows installers, RBAC console.
Alternatives in Security
- Anthropic Cybersecurity Skills — 734+ structured cybersecurity skills for AI agents · MITRE ATT&CK mapped · agentskills.io open standard · Work 3.8k ★
- Audit Agent Sessions — Analyze all agent sessions from the last 3 days across Claude, Codex, and Gemini 238 ★
- Airsec — Find Security Issues in your code by using coding CLIs like Claude, Codex & CommandCode 162 ★
README
Aegis AI Agent Security
Aegis 是面向企业终端的 **AI Coding 安全治理**工具。它在员工电脑上随 AI 编码工具运行一个轻量 Agent,**只读**发现本机受管的 AI Agent / Skill / MCP,加载企业安全编码基线,扫描 Skill、MCP、代码质量、依赖与密钥风险,并上报到受认证的接收器(Collector);私有控制台用于研判、处置、**签名策略下发**、版本态势与审计。
遵循**单端原则**:员工终端只安装 Aegis 一个 agent,其余平台(EDR / 桌管 / 开源安全栈)通过适配边界协同,不重复装探针。
**当前发行**:产品 `0.71.0`(pilot)· Endpoint Agent `0.32.0` · 策略出厂 `4.8.0`(控制台发布件递增 `4.9.0+`)· Collector `0.15` · Adapter `0.7`。
支持的 AI Coding 工具
Agent 通过**只读文件标记**识别下列工具(不启动、不执行被发现的 Agent),发现其 Skill / MCP / 配置并纳入治理:
| 工具 | 标识 | 工具 | 标识 |
|---|---|---|---|
| Cursor | cursor |
GitHub Copilot CLI | github_copilot_cli |
| Claude Code | claude_code |
QwenWork / 通义千问 | qwen_enterprise |
| Codex CLI | codex_cli |
通义灵码 | tongyi_lingma |
| Windsurf | windsurf |
CodeBuddy | codebuddy |
| Gemini CLI | gemini_cli |
WorkBuddy | workbuddy |
另支持登记为「其他工具」。工具清单在三处保持同步:`aegis_agent.py` 的发现标记、`lib/store.ts` 的类型、控制台设备表单选项。
**平台**:macOS 与 Windows 提供原生安装器;Python Agent 亦可运行于 Linux。
控制台能力
| 页面 | 作用 |
|---|---|
| 总览 / 快速开始 | 实时安全态势;五步接入引导(连接接收器 → 部署 Agent → 研判 → 处置 → 基线下发) |
| 设备与 Agent | 终端清单、在线/覆盖、版本姿态(Agent/策略是否漂移) |
| 风险中心 | 工单队列与状态机(待处理→认领→调查→解决/驳回)、关联发现、命中证据「详细信息」 |
| 处置中心 | 对 Skill / MCP 打标:加白 / 观察 / 拉黑,编译进下发策略 |
| Skill / MCP / 代码质量扫描器 | 分域查看扫描结果与趋势 |
| 扫描引擎 | 内置引擎 + Semgrep / Gitleaks / Cisco skill-scanner / Snyk(引擎独立,不互转规则语法) |
| 策略配置 | 签名策略发布(aegis.policy/v1,HMAC 签名 + 密钥环轮换),终端可拉取强制执行 |
| 基线管理 | 企业自定义编码基线导入 + 上游基线同步 |
| 审计日志 | 全操作留痕(含自动入网、策略发布、令牌轮换等) |
| 团队与权限 | 三级 RBAC:管理员 / 审计员 / 只读 |
| 系统设置 | 扫描模式(quick / standard / custom)等全局配置 |
| 接入中心 | Collector 连接与厂商适配(EDR / 桌管)集成 |
控制台基于 vinext(Next.js on Cloudflare Workers)+ PostgreSQL 持久化;未连接接收器时**诚实显示空态/演示模式,绝不伪造数据**。
终端零接触入网(装完即被纳管)
拿到客户端、连到正确的服务器地址,即**自动获得上报令牌与当前策略**,无需管理员手动逐台下发:客户端调用 `POST /api/enroll`(会话豁免、限流、审计、可选入网密钥门),取回上报令牌、每设备独立签名密钥与**去签名的已发布策略**(经 TLS 信任加载,不暴露签名/验签密钥)。
# macOS —— 原生 .pkg(双击安装;postinstall 自动入网 + 系统 LaunchDaemon,开机自启)
sud
Related Skills
Elementor Headless
Safely audit and edit WordPress + Elementor sites - AI-agent skill for Claude Code, Cursor, Codex CLI, Gemini
Skillen
Audit your AI coding skills using your real conversation history — find the toxic ones wasting tokens. Support
Hackz Huntkit
Offensive-security playbooks for AI coding agents — IDOR, 403 bypass, CORS, finding validation and dupe-checki
AuraKit
npx @smorky85/aurakit Fullstack development skill with 37 modes (BUILD/FIX/CLEAN/DEPLOY/REVIEW + 32 extended),
Agent Security Hooks
Security hooks for AI coding assistants (Claude Code, Cursor, Gemini CLI) - block dangerous commands, protect
Cocoaskills
Local skill manager for AI agent skills: reproducible per-project installs, skill dependencies, security audit
Related Agents
Developer Overview
code-container (container) creates isolated Docker environments for AI coding harnesses (Claude Code, OpenCode
Consult Agent
Execute cross-tool AI consultations via Task spawning. Use when agents or workflows need a second opinion from
10x Tool Calls
Cursor and Windsurf meter usage by requests and tool calls rather than tokens, which means a finished or stall