security-boundary-contract
CommunityPrevent insecure actions across the whole agent platform.
Legal & Compliance#authorization#secret management#security policy#iframe sandbox#audit testing#tool safety#error redaction
Authorzxc1a1a1
Version1.0.0
Installs0
System Documentation
What problem does it solve?
It defines AgentHub’s end-to-end security boundary so engineers, reviewers, and AI agents can consistently decide what is untrusted, what must be authorized, and what must never be leaked.
Core Features & Use Cases
- Trust boundary model: Establishes which inputs and outputs (user, Frontend fields, LLM/Planner, Agent outputs, AgentCards, artifacts, tool call parameters) are untrusted and must be validated before execution.
- Security contract for each layer: Specifies public API rules for Frontend→Gateway, service-to-service constraints for Gateway↔Orchestrator, orchestration guardrails, and Child/User Agent trust levels.
- High-risk action governance: Enforces confirm_action for dangerous capabilities (run_command, deploy, file_overwrite, external_publish, etc.) plus requirements for schema validation, permission checks, timeouts, and auditing.
- Data protection and rendering safety: Provides artifact/runtime capability risk levels, iframe sandbox/CSP/XSS defenses, and strict error redaction to stop secret leakage.
- Security testing & review checklist: Includes minimal contract tests and a structured review checklist to verify the boundary stays intact across v1.0 evolution.
Quick Start
Ask an AI reviewer to use security-boundary-contract to produce an audit plan for your Gateway and Orchestrator changes, including required confirm_action gates, object-level authorization checks, and redaction rules for errors and artifacts.
Dependency Matrix
Required Modules
None requiredComponents
references
💻 Claude Code Installation
Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.
Please help me install this Skill: Name: security-boundary-contract Download link: https://github.com/zxc1a1a1/Multi_Agent-AgentHub/archive/main.zip#security-boundary-contract Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
Agent Skills Search Helper
Install a tiny helper to your Agent, search and equip skill from 471,000+ vetted skills library on demand.