Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIGitHub CopilotGitHub CopilotGemini CLIGemini CLI+20 more

    Agent Security and Red Team Pattern Library

    2

    Most teams harden against the two they've heard of and miss the ten they haven't.

    $24

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    2 installsSecurity scanned
    Agent Security and Red Team Pattern Library

    Agent Security and Red Team Pattern Library

    Example session with this skill installed

    Threat-model my email assistant agent. It can read my inbox, summarize threads using RAG, and has a tool to send replies. What are the high-severity risks and how do I fix them?

    • Read your context and instructions
    • Compiled the agent security

    Attack surface (from attack-surface-map.md): untrusted inbox content, the RAG store, and the reply-sending tool are your three exposed edges.

    HIGH — Indirect prompt injection (prompt-injection-patterns.md): a malicious incoming email carries instructions that hijack the agent. Detection signal: model output that references sending, forwarding, or new recipients not present in the user's request. Defense: treat all email body text as untrusted data, never instructions; require human confirmation before any send.

    HIGH — Tool abuse / destructive triggering of the send tool (tool-abuse-patterns.md). Detection signal: send calls whose recipients or content don't trace to a user request. Defense: human-in-the-loop on send, scope the tool to reply-only, and block new external recipients.

    MEDIUM — RAG corpus poisoning (rag-and-retrieval-attacks.md): poisoned threads bias summaries. Detection signal: retrieved context that asserts instructions. Defense: provenance tagging and retrieval sanitization.

    Each finding maps to a mitigation in defense-patterns.md, and the threat-model-worksheet.md gives you the full worked pass to complete for the remaining surfaces.

    Attack surface (from attack-surface-map.md

    Connects securely to your tools. The creator never sees your data.

    What you get

    Map the attack surface of an agent system to identify hidden entry points.Identify detection signals for indirect prompt injection and RAG poisoning.Create a prioritized defense plan based on potential blast radius.Evaluate the security risks of giving an agent access to third-party APIs.

    About this skill

    As agents gain tools, memory, and the ability to read untrusted content, they gain an attack surface — and the attacks have known shapes, scattered across papers, disclosures, and other people's incidents. Most teams harden against the two they've heard of and miss the ten they haven't. This is the catalog. It is a defensive reference — a field manual for hardening agents you build or operate, describing attacks so you can recognize and close them, not an offensive toolkit and not a source of weaponized payloads. It maps every surface where untrusted input reaches an agent, then walks six attack families in depth: prompt injection (direct, indirect, hidden-channel, deferred, multi-modal), tool abuse (unauthorized invocation, argument manipulation, tool chaining, confused deputy, destructive triggering), data exfiltration (system-prompt disclosure, cross-tenant bleed, outbound-argument and rendered-content channels, memory and aggregation), memory and context attacks (poisoning, cross-session and cross-user persistence, saturation, compaction tampering), multi-agent attacks (injection propagation, delegation abuse, confused deputy, orchestrator compromise, result poisoning), and RAG and retrieval attacks (corpus poisoning, ranking abuse, citation laundering, index attacks, retrieval-driven exfiltration). Every pattern is written the same way — the surface it hits, how it works conceptually, the detection signal, the concrete defense, and a blast-radius severity — so it reads as a catalog you can scan, not an essay. It closes with a defense-pattern catalog of twelve mitigations, each mapped back to the attacks it closes and ordered by leverage, and a threat-model worksheet with a fully worked hardening pass on a coding-assistant agent. The download is ten files in total. It is a defensive reference and design aid for systems you own or are authorized to test — it does not attack third-party systems, execute exploits, access your agent, or guarantee security, and it describes attacks conceptually for defense rather than shipping exploitation steps. Security is not a one-time state: passing every pattern here is a strong baseline, not a certificate. Works with Claude Code, Cursor, Codex CLI, Gemini CLI, and any SKILL.md agent.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    2 installs

    Downloaded by developers to date

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 2 months ago

    • Passed all security checks, Safe to install

    Listed2 months ago
    Updated2 days ago

    What's inside

    Frequently Asked Questions