infra-security

Audit AICP security posture across secrets, guardrails, exposure, and supply chain.

Updated Mar 26, 2026
One-click install
npx skills add https://github.com/cyberpunk042/devops-expert-local-ai --skill infra-security-cyberpunk042
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: infra-security
Source: https://github.com/cyberpunk042/devops-expert-local-ai/tree/main/.claude/skills/infra-security
Command: npx skills add https://github.com/cyberpunk042/devops-expert-local-ai --skill infra-security-cyberpunk042

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Audits AICP's security posture across four critical layers to identify secrets exposure, guardrails enforcement gaps, runtime exposure risks, and supply-chain integrity, enabling proactive risk management.

Core Features & Use Cases

  • Inventory secrets: verify env vars and tokens are not leaked or committed.
  • Validate guardrails: verify path and response enforcement are active and effective.
  • Assess exposure: map ports, MCP server access, and cloud token blast radius.
  • Review supply chain: check dependencies, model integrity, and image pinning.

Quick Start

Run an on-demand security audit against the current AICP deployment to surface vulnerabilities and generate a traceable findings report.

Frequently Asked Questions about infra-security

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I audit security posture and check for exposed secrets before deployment?

Run an on-demand security audit to inventory environment variables and tokens, verifying they are not leaked or committed. This surfaces vulnerabilities across secrets, guardrails, exposure, and supply-chain integrity to enable proactive risk management.

How do I verify guardrails enforcement and assess exposed interfaces in my environment?

Verify guardrails by checking that path and response enforcement are active and effective. Assess exposed interfaces by mapping ports, MCP server access, and cloud token blast radius to identify unintended runtime exposure risks.

Can I check dependencies and model integrity to ensure supply-chain security?

Yes, you can review the supply chain to check dependencies, model integrity, and image pinning. This verifies your dependencies and model integrity while producing a read-only audit log for traceable findings.

When should I run an end-to-end security audit after configuration changes?

Apply an end-to-end security audit before fleet deployment, after configuration changes, or after security incidents. This verifies there are no secret leaks, unintended exposures, or vulnerable dependencies introduced during the changes.

What is the best way to map cloud token blast radius and generate a traceable findings report?

The best way to map token blast radius is to run a security audit that assesses exposed interfaces and inventories tokens. It automatically generates a read-only audit log serving as a traceable findings report.