Dispatch independent tasks to parallel workers or subagents without write collisions. Use when: running or planning agents in parallel, even two; check scopes before any launch.
日本語の概要は準備中です。原文の説明を表示しています。
Review code for security problems; scan for vulnerabilities, secrets, dependency and prompt risks. Use when: asked whether code is safe to ship, even one small handler.
インストール方法を見るインストールする前に、エージェントに与えられる指示の中身を確認できます。
Purpose: Find and report security weaknesses in code, scripts, authorized binaries, and repo-managed prompt surfaces, with honest coverage.
Use this skill for a caller-requested security review of code, a repository scan, authorized binary assurance, dependency risk, secrets, or offline prompt-surface redteam.
--require-tools when complete tool coverage is required. Why: absent evidence is not evidence of absence.Apply these to every review, scripted or manual. They are the rules most often skipped:
target: <paths, endpoints, or binary>; authorization: <boundary>
findings: <id> <severity> <file:line> <class>: <what>
proven: <input run> | suspected: <candidate input, why not run>
fix class: <a few words>
coverage: <class> -> finding <ids> | clean | not assessed (<why>)
tools: <scanner or command> -> ran | missing | error
hunt: converged after <n> passes | unconverged | not run
Code-level review and redteam passes work in any repository, with or without AgentOps tooling. Walk the ledger against the full surface and probe fail-open behavior where that is safe. Repeat full passes until one complete pass adds no new finding and no new coverage gap; that quiet round is the stop condition. If the budget ends first, report the hunt as unconverged. The quiet-round rule applies only to the manual hunt.
Each selected scan runs once per request; a rerun is a new caller decision.
| Surface | Entry point | Location |
|---|---|---|
| Repository gate (quick or full) | scripts/security-gate.sh | AgentOps repository root only |
| Composable suite for authorized binaries | skills/security/scripts/security_suite.py | this skill's scripts/ |
| Offline prompt-surface redteam | skills/security/scripts/prompt_redteam.py | this skill's scripts/ |
This is the canonical security runbook. Suite policy gating produces machine-consumable outputs, including policy/policy-verdict.json when a policy file is supplied.
scripts/security-gate.sh --mode quick # changed scope
scripts/security-gate.sh --mode full # repository-wide
Add --require-tools when skipped scanners would invalidate the assurance
claim. Checkpoint: preserve the exit code and verify the reported
security-gate-summary.json exists and parses before triage; report the result
as incomplete unless the selected artifact validator and process both succeed.
Scheduled automation runs the full gate against the intended branch and retains its artifact directory. A failing scheduled run creates actionable tracked work; AgentOps itself does not supply the scheduler.
Artifact directory: repository gates write ${SECURITY_GATE_OUTPUT_DIR:-${TMPDIR:-/tmp}/agentops-security}/<run-id>/; composable-suite and redteam runs use their explicit --out-dir.
Filename convention: repository gates require security-gate-summary.json (and raw summary.json); suite runs require suite-summary.json; redteam runs require redteam/redteam-results.json.
Serialization/schema format: security-gate-summary.json is JSON with nonempty mode, run_id, output_dir, and gate_status, numeric missing_tool_count, boolean require_tools, and object toolchain.
Validator command: with OUT=<security-gate-run-dir>, run jq -e '(.mode|type)=="string" and (.mode|length)>0 and (.run_id|type)=="string" and (.run_id|length)>0 and (.output_dir|type)=="string" and (.output_dir|length)>0 and .gate_status=="PASS" and (.missing_tool_count|type)=="number" and (.require_tools|type)=="boolean" and (.toolchain|type)=="object"' "$OUT/security-gate-summary.json" >/dev/null.
Output: the review report above; for scripted scans also the artifact path, command/exit code, mode, and gate status. Do not add an owner, next action, approval, release, ship, or retry decision.
Run the skill and redteam validators:
bash skills/security/scripts/validate.sh
bash tests/scripts/test-security-suite-redteam.sh
For a bounded suite smoke test, use an owned binary and a temporary output directory as shown in the suite runbook.
| Problem | Response |
|---|---|
| Scanner missing/error | Record the coverage gap; install it or rerun with --require-tools when required |
| Local/CI mismatch | Compare scanner versions, config, mode, and both artifact directories |
| Suspected false positive | Reproduce narrowly; document any authorized suppression and its owner |
| Suite/baseline failure | Inspect the named compare/policy artifact; never refresh baseline reflexively |
| Redteam failure after wording change | Decide whether the control regressed or the attack-pack matcher needs intentional revision |
まだレビューはありません。使ってみた感想をお寄せください。
概要と使いどころ
Dispatch independent tasks to parallel workers or subagents without write collisions. Use when: running or planning agents in parallel, even two; check scopes before any launch.
日本語の概要は準備中です。原文の説明を表示しています。
Run a supplied task in headless AGY (Antigravity, Gemini) and collect its result. Use when: AGY, Antigravity or Gemini is requested by name; never a fallback.
日本語の概要は準備中です。原文の説明を表示しています。
Run one prompt through headless Claude with scoped permissions and a time bound. Use when: scripting or automating a `claude -p` call, even a simple one.
日本語の概要は準備中です。原文の説明を表示しています。
Run one prompt through headless Codex and capture the result. Use when: wanting a one-shot `codex exec` run or CI step. Not for batches or retries.
日本語の概要は準備中です。原文の説明を表示しています。
Compare independent opinions from several models or contexts without inflating agreement. Use when: wanting a second opinion or debate, or summarizing several reviewers' results.
日本語の概要は準備中です。原文の説明を表示しています。
Draft or lint a bounded long-running goal prompt with a finish line and hard limits. Use when: selected by name; one change goes to Plan.
日本語の概要は準備中です。原文の説明を表示しています。