slowmist-agent-security-framework

Review AI skill installations and external inputs for security threats.

11|1|Updated May 16, 2026
One-click install
npx skills add https://github.com/Aradotso/security-skills --skill slowmist-agent-security-framework
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: slowmist-agent-security-framework
Source: https://github.com/Aradotso/security-skills/tree/main/skills/slowmist-agent-security-framework
Command: npx skills add https://github.com/Aradotso/security-skills --skill slowmist-agent-security-framework

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps prevent AI agents from installing or acting on unsafe skills, repositories, URLs, on-chain addresses, and external services by enforcing a verification-first security review workflow.

Core Features & Use Cases

  • Skill/MCP Installation Review: evaluates skills and MCPs for malicious patterns before activation, including obfuscation, credential access, code execution, and network exfiltration risks.
  • GitHub Repository Auditing: assesses repository trust through metadata and evidence-based red-flag scanning, including supply-chain risk considerations.
  • Untrusted Input Analysis (URL/Document, On-Chain, Services): identifies prompt injection, social engineering, and AML/on-chain risk factors, and produces risk-ranked reports to guide safe next actions.

Quick Start

Use the slowmist-agent-security-framework to review a proposed skill installation source and generate a risk level with actionable findings before the agent proceeds.

Frequently Asked Questions about slowmist-agent-security-framework

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I review AI skills for prompt injection and malicious code execution risks?

AI skill security review involves evaluating proposed installations for obfuscation, credential access, code execution, and network exfiltration patterns. This framework applies threat-aware checks and red-flag scanning to generate a risk rating with actionable findings before agent activation proceeds.

What is threat modeling for AI agent installations and external inputs?

Threat modeling for AI agent installations is a verification-first security workflow that assesses untrusted content like GitHub repositories, URLs, and on-chain addresses. It identifies supply-chain compromise, social engineering, and prompt injection risks to produce risk-ranked reports for safe agent actions.

How do I audit a GitHub repository for supply chain risk before using it?

Auditing a GitHub repository for supply chain risk requires assessing repository trust through metadata and evidence-based red-flag scanning. This framework evaluates untrusted repositories to identify potential compromise factors and generates a risk level to determine if human approval gates are needed.

Can I analyze blockchain addresses for on-chain AML risk factors?

You can analyze blockchain addresses for on-chain AML risk factors using this framework's untrusted input analysis feature. It identifies risk factors associated with on-chain addresses and produces risk-ranked reports to guide safe next actions for your AI agent.

Does this security review framework support human approval gates for higher-risk cases?

This security review framework supports human approval gates for higher-risk cases by enforcing a verification-first workflow. It requires following review guides, red-flag pattern checks, and trust-tier assessments to output a risk rating that triggers human approval when elevated risks are detected.

When do I need a security review for MCP installation?

You need a security review for MCP installation when evaluating skills and MCPs for malicious patterns before activation. This framework checks for obfuscation, credential access, code execution, and network exfiltration risks to prevent AI agents from acting on unsafe external services.