slowmist-agent-security

Analyze external inputs and configurations for security risks and prompt-injection vulnerabilities.

4|Updated Mar 18, 2026
One-click install
npx skills add https://github.com/evilcos/slowmist-agent-security --skill slowmist-agent-security
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: slowmist-agent-security
Source: https://github.com/evilcos/slowmist-agent-security/tree/main
Command: npx skills add https://github.com/evilcos/slowmist-agent-security --skill slowmist-agent-security

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

The SlowMist Agent Security Review framework provides a structured approach to auditing external inputs for AI agents, preventing exploitation, data leakage, and prompt-injection risks by guiding thorough review workflows.

Core Features & Use Cases

  • Skill/MCP installation reviews to detect malicious patterns before installation
  • Repository, URL/document, on-chain, product/service, and social-share reviews with standardized templates
  • Comprehensive risk rating, trust assessment, and guardrails for human-in-the-loop decisions

Quick Start

Provide a security review on a given skill, repository, or URL and produce a structured risk assessment.

Frequently Asked Questions about slowmist-agent-security

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I check a GitHub repository for prompt-injection vulnerabilities before using it with an AI agent?

To check a GitHub repository for prompt-injection risks, the framework analyzes external inputs and project configurations using standardized templates to detect malicious patterns and output a structured risk assessment. It evaluates trust levels to prevent data leakage and exploitation.

Can I review an on-chain address for security risks before integrating it into my AI workflow?

You can review an on-chain address for security risks by submitting it to the assessment workflow. The framework evaluates the address alongside URLs and documents, applying universal templates to generate a trust assessment and risk rating for your AI agent integration.

What is the best way to detect malicious patterns in Skill or MCP installations?

The best way to detect malicious patterns in Skill or MCP installations is to run a pre-installation security review. The framework audits configurations and external inputs to identify prompt-injection vulnerabilities and outputs a risk rating requiring human approval for high-risk decisions.

Does the security review framework support human-in-the-loop approvals for high-risk assessments?

The security review framework supports human-in-the-loop approvals by requiring human approval for HIGH or REJECT decisions. It outputs universal risk ratings and trust assessments to guide thorough review workflows, preventing automated exploitation when evaluating external inputs.

How do I assess the security of a product or service integration for my AI agent?

To assess the security of a product or service integration, the framework analyzes the external inputs and configurations for prompt-injection vulnerabilities. It uses standardized templates to produce a comprehensive risk rating and trust assessment to guide your integration decisions.