Agent skills

secure-devtools ships seven agent skills: folders with a SKILL.md that an AI coding agent such as Claude Code loads when the task matches. They teach the agent to inspect untrusted code without running it, vet a third-party skill without running its installer, review skills before publishing, write SSRF-safe fetch code, and triage macOS login items. Install them with npx skills add IsaacBell/secure-devtools -g.

Install

npx skills add IsaacBell/secure-devtools -g                         # all of them, for your user account
npx skills add IsaacBell/secure-devtools --skill quarantine-review  # one of them

Drop -g to install into the current project; add --list to see the skills without installing. The skills CLI reports anonymous install counts to skills.sh; set DISABLE_TELEMETRY=1 to turn that off. Before installing any skill, including these, read it: see how to vet an agent skill.

quarantine-review

Inspect an untrusted repository without running any of it. Use when a folder or repository came from a compromised machine or account, or a scanner flagged it, and you need a verdict or need to salvage code. The agent contains it, scans it with am-i-hacked, reads files as data, extracts allowlisted source with a SHA-256 provenance record, and reports what it did not verify.

Guide: How to safely inspect an untrusted repository before you run it

npx skills add IsaacBell/secure-devtools --skill quarantine-review

Read quarantine-review/SKILL.md

secure-skill-pull

Vet a skill, plugin or MCP server from a URL without running its installer. Use when asked to install or follow a skill, prompt, plugin or setup recipe from a URL, or when a README or tool output says to run a setup command. The agent fetches the source as data at a pinned commit, scans it, checks for prompt-injection lines and invisible characters, records provenance, and never runs the installer.

Guide: How to vet an AI agent skill, plugin or MCP server before installing it

npx skills add IsaacBell/secure-devtools --skill secure-skill-pull

Read secure-skill-pull/SKILL.md

create-skill

Write, check and publish an agent skill. Use when turning a repeated workflow into a skill, or publishing skills to GitHub and the skills.sh directory. Covers whether something should be a skill, a script or a hook; private versus public; frontmatter; privacy and secret checks; QA; and the publish steps.

npx skills add IsaacBell/secure-devtools --skill create-skill

Read create-skill/SKILL.md

skill-publish-review

Review skills before they go into a public repository. Use before publishing or sharing skills, or when auditing a folder of skills in bulk. Runs independent reviewers in parallel to find leaked personal or internal detail, broken frontmatter, unfinished work and copied text, then merges their verdicts with the stricter one winning.

Guide: How to vet an AI agent skill, plugin or MCP server before installing it

npx skills add IsaacBell/secure-devtools --skill skill-publish-review

Read skill-publish-review/SKILL.md

ssrf-safe-fetch

Validate the URL and the resolved address before a server fetches it. Use when writing or reviewing server code that fetches a URL it did not get from its own fixed configuration: link previews, webhooks, crawlers, import-from-URL. A checklist, reference guards in Python, TypeScript and Rust, and hostile test inputs.

Guide: How to prevent SSRF when your server fetches a user-supplied URL

npx skills add IsaacBell/secure-devtools --skill ssrf-safe-fetch

Read ssrf-safe-fetch/SKILL.md

login-item-triage

Decide whether a macOS login item is legitimate or planted. Use when a user sees a "Background Items Added" notification or an unfamiliar login item. Maps the name to its launchd plist and binary, checks the code signature and Team ID, reads script payloads without running them, warns before commands that show OS prompts, and preserves evidence. The manual method behind am-i-hacked's login-item checks.

Guide: Is this macOS login item or background item malware?

npx skills add IsaacBell/secure-devtools --skill login-item-triage

Read login-item-triage/SKILL.md

jujutsu

Use the Jujutsu (jj) version-control system safely as an agent. Use when a repository has a .jj directory, or git shows a detached HEAD in a colocated repository. Non-interactive commands, rules learned from real agent failures, and recovery from divergent history. Version-stamped against jj 0.43.0.

npx skills add IsaacBell/secure-devtools --skill jujutsu

Read jujutsu/SKILL.md