plugins/cli-agents/skills/agt-security/SKILL.md
Provides sandboxing validation, HMAC key rotation, and budget verification to manage security boundaries under Agentic Group Theory (AGT).
npx skillsauth add richfrem/agent-plugins-skills agt-securityInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
This skill contains tools and reference materials to manage secure local execution sandboxes, verify process hygiene limits, and rotate cryptographic bus keys.
To verify that the sub-agent execution environment complies with AGT process hygiene or containerized sandboxing:
python3 plugins/cli-agents/scripts/agt_ops.py verify-sandbox
This performs:
ANTHROPIC_API_KEY, PYTHONPATH) are scrubbed inside subprocesses.To generate or rotate the HMAC symmetric key used to sign messages across the local control plane:
python3 plugins/cli-agents/scripts/agt_ops.py rotate-key
Keys are rotated dynamically and written to ${CLAUDE_PROJECT_DIR}/context/exploration/.secrets/session_hmac.key with restricted 0600 permissions.
testing
Skill for creating and managing isolated git worktrees (`.worktrees/issue-NNN`) for issue execution branches. USE ONLY when setting up or cleaning up isolated git worktrees for specific issue execution. DO NOT USE for managing local task files (use `task-agent`) or escalating tasks to issues (use `github-issue-backlog-agent`).
data-ai
Skill for orchestrating the end-to-end GitHub issue lifecycle flow: Issue -> Worktree -> Implementation -> PR Creation -> Resolution Closure. USE ONLY when running or dry-running full lifecycle orchestration for resolving an issue with a PR. DO NOT USE for isolated worktree management only (use `issue-worktree-agent`) or logging issues (use `github-issue-agent`).
tools
Automatically ranks GitHub issues (P0-P3) based on friction tier, frequency, and blockages, synchronizing priority labels and GitHub Projects v2 custom fields.
testing
Bridge skill for escalating ephemeral local task scratchpad items (`tasks/*.md`) into durable, taxonomy-validated, evidence-rich GitHub Issues. USE ONLY when promoting a single-session local task into durable repository backlog. DO NOT USE for managing local kanban boards (use `task-agent` instead) or directly querying/commenting on issues (use `github-issue-agent` instead).