More screenshots

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIGitHub CopilotGitHub CopilotGemini CLIGemini CLI+20 more

    AI Agent Security Guardrail

    2

    Scans AI-generated code for hardcoded secrets and unsafe dynamic call sites, applies safe fixes, and produces a before/after security report — local only, no network.

    $9.99

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    0 installsSecurity scanned
    AI Agent Security Guardrail

    AI Agent Security Guardrail

    Example session with this skill installed

    I just finished a feature with my AI coding agent and I'm about to commit it. Please run a security pass on the changed code.

    Focus on

    1. Hardcoded API keys or other credentials
    2. eval()/exec() usage
    3. Whether any critical or high-severity findings can be safely fixed automatically

    Use the current git diff as the primary scope. Apply only high-confidence automatic fixes, validate the changed files afterward, and give me a concise before/after security report. Clearly identify anything that still requires human review.

    • Read your context and instructions
    • Compiled the ai agent security
    • Generated the document

    Security Guardrail Report

    Verdict: Fix before shipping

    The security pass found two high-risk issues in the AI-generated changes. One exposed credential was safely moved to an environment variable, while an unsafe eval() path remains for human review because automatically replacing arbitrary evaluation could change application behavior.

    Summary

    SeveritySecretsEval/ExecStatus
    Critical10Fixed
    High01Manual review
    Medium00—
    Low00—

    Findings

    1. Critical — Hardcoded API credential

    File: src/config.py:18

    A credential-like value was embedded directly in source code.

    Risk: A real credential committed to source control can be exposed through git history, logs, backups, forks, or repository access.

    Action: Automatically replaced the literal with an environment-variable lookup and added a safe placeholder to .env.example.

    Validation: Python syntax validation passed after the change.

    Important: If the original value was a real credential, rotate or revoke it. Removing the literal from the working tree does not remove it from existing git history.

    2. High — Potentially unsafe eval()

    File: src/agent_parser.py:42

    eval() receives a variable whose provenance is not sufficiently trusted or validated.

    Risk: If attacker-controlled or LLM-generated content reaches this call, it may become an arbitrary code-execution path.

    Action: Not automatically changed.

    The expression does not meet the narrow safe-replacement criteria for automatic remediation. Replacing it blindly could alter application behavior.

    Status: Manual review required.

    Recommended next steps

    1. Rotate the exposed credential if it was real.
    2. Confirm the new environment variable is configured in the deployment environment.
    3. Review the data flow into eval() and determine whether it can receive user, HTTP, CLI, or LLM-generated input.
    4. Prefer structured parsing or an allow-listed operation model instead of arbitrary code evaluation.
    5. Run the project's normal test suite before committing.
    6. Re-run the security guardrail after remediation.

    Scan boundary: This review was limited to the current git diff. Existing vulnerabilities outside the changed files were not treated as part of this pass.

    ai-agent-security-guardrail.pdf

    PDF · document

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Scan git diffs for leaked API keys before committing code.Convert hardcoded credentials to environment variables automatically.Replace dangerous eval() calls with safe alternatives like JSON.parse.Verify that .env files are properly excluded from git version control.

    About this skill

    AI coding agents move fast and often leave two problems behind: API keys hardcoded in source, and dynamic execution wired to LLM or user input.

    This skill runs a focused local security pass on the file, diff, or repo you choose:

    • Detects known key shapes (AWS, Stripe, GitHub, Anthropic, OpenAI, PEM, …) plus high-entropy secret-like assignments • Detects unsafe dynamic call sites and estimates whether input looks untrusted • Auto-fixes critical/high secrets → environment variables (+ .env.example + .gitignore check) • Narrow, safe rewrite of simple expression calls → JSON.parse / safe AST literal parsing • Leaves statement-execution and unclear cases for manual review • Outputs a short ship / fix / do-not-ship report

    No outbound network. No execution of scanned code. Standard library only. Ideal right after an agent finishes a feature, before commit or PR.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 27 days ago

    • Passed all security checks, Safe to install

    Listed27 days ago

    What's inside

    Frequently Asked Questions