AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified Apache-2.0 Self-run

Verify Security

skill-easyinplay-harnessed-security · by easyinplay

|

No reviews yet
0 installs
26 views
0.0% view→install

Install

$ agentstack add skill-easyinplay-harnessed-security

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-easyinplay-harnessed-security)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
2mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Verify Security? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

verify-security workflow (v3)

Overview

1-phase sub-workflow mapping CLAUDE.md "Verify 阶段 — 可选 /cso" onto harnessed runtime (Phase v3.0-3.4 W0.13b — D-04 Stage ④ Verify 7 sub + D-12 gstack 治理关卡 + Pattern A sub-workflow ship)。

| phase | id | upstream | model | capability | gate | | ----- | -- | -------- | ----- | ---------- | ---- | | 1 | 01-cso | gstack | opus | {{ capabilities.gstack-cso.cmd }} | judgments.stage-routing.verify-security-secrets.fires |

Per-phase config loads from workflows/verify/security/workflow.yaml; engine 4-level gate resolver evaluates phase.has_auth_or_secrets == true via expr-eval — true 则 invoke gstack /cso (OWASP / auth / credentials / secrets 全面审查), false 则 skip。

Capability refs

Sister workflows/capabilities.yaml entries:

  • gstack-cso — Bucket 3 治理关卡 (impl: gstack, cmd: /cso,

fireswhen: phase.stage == 'verify' AND phase.hasauthorsecrets == true)

Gate ref

Sister workflows/judgments/stage-routing.yaml:

  • verify-security-secrets.firesphase.stage == 'verify' and phase.has_auth_or_secrets == true

Routing rules

  • 触发: auth flow / session / credentials / API keys / SQL injection 路径 / OWASP top 10 area
  • 跳过: docs / 纯 UI styling / 内部 refactor / non-security PR

How to invoke

!harnessed checkpoint intent verify-security

> The banner above (when present) means this invocation is REGISTERED with the engine (an intent marker) — not yet compliant: the steps below (prompt → spawn → checkpoint complete) resolve it, and a per-turn `` reminder persists until they run.

The numbered sequence below is the state machine — execute it with Bash. Do NOT improvise an equivalent flow from the Overview above: freelancing bypasses the engine (no ledger, no evidence guard). harnessed gives you the spawn-ready prompt; YOU spawn the subagent with a CC-native Task / Agent tool (keeps the session responsive + lets clarification round-trips reach the user).

Do NOT pipe to harnessed run verify-security — that is the CI/headless path (in-process SDK spawn that blocks the session inside Claude Code).

  1. Bash: harnessed prompt verify-security --task "$ARGUMENTS" --json → parse {prompt, max_iterations, model}.
  2. Spawn a CC-native subagent (Task / Agent tool) with that prompt + model, wrapped in the ralph-loop plugin: /ralph-loop "" --max-iterations --completion-promise "COMPLETE". If the plugin is absent, use the native goal gate instead (Claude Code 2.1.139+ / Codex): /goal "this subtask is delivered: the subagent's final output contains verbatim COMPLETE; or stop after turns" then spawn the subagent and let the goal evaluator drive re-spawns until it clears. If /goal is unavailable too, self-loop: spawn → check output for COMPLETE → re-spawn with prior output appended (up to max_iterations). Set the goal only at the leaf subtask level — /goal is single-slot per session and a nested goal overwrites the outer one.
  3. If the output contains STATUS: NEEDS_CLARIFICATION + a question list: STOP, relay them verbatim via AskUserQuestion, append the answers to the spec, then re-spawn the same sub.
  4. On COMPLETE: Bash harnessed checkpoint complete verify-security --summary "". The evidence guard runs here (fail-CLOSED): if a declared artifacts_expected file is missing it exits non-zero — re-spawn to produce it before treating the sub as done.

References

  • D-04 Stage ④ Verify 7 sub 分解
  • D-12 gstack 治理关卡可选
  • workflows/capabilities.yaml — gstack-cso
  • workflows/judgments/stage-routing.yaml — verify-security-secrets trigger
  • workflows/verify-work/workflow.yaml v2 SHIPPED phase 06-cso-conditional sister verbatim

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.