security-ai
Security review for LLM applications, AI agents, MCP servers and clients, the AI and ML supply chain, and repositories that ship agent skills or plugins. Covers prompt injection and indirect injection, exfiltration paths, agent permission and sandbox hardening, MCP authorization requirements, model, dataset and pickle provenance, AI red-teaming tool selection, and restricted model-assisted vulnerability analysis. Skip it when no model or agent sits in the trust path and a conventional application, infrastructure, or dependency review applies, and skip it for legal or compliance sign-off.
Pinned to revision 6335fa80c2f6, so it is the text this page describes rather than whatever the author pushed since.
Files
- skills/security-ai/SKILL.md
- skills/security-ai/assets/restricted-analysis-profile.template.json
- skills/security-ai/references/agent-runtime-hardening.md
- skills/security-ai/references/ai-supply-chain.md
- skills/security-ai/references/llm-application-review.md
- skills/security-ai/references/mcp-server-review.md
- skills/security-ai/references/red-teaming-tools.md
- skills/security-ai/references/restricted-vulnerability-analysis.md
- skills/security-ai/scripts/validate_restricted_analysis_profile.py
Every link opens the file at its source, pinned to the revision this page describes.