whyashthakker/beam-cli▌
30 approved skills in this repository
agent-cost-abuse-review
agent-cost-abuse-review
### agent-cost-abuse-review - Review agent deployments for runaway spend, quota and rate-limit abuse, and resource exhaustion — token/API budget controls, loop and retry - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
agent-permissions-review
agent-permissions-review
### agent-permissions-review - Review an AI agent's effective filesystem, execution, network, tool, and credential permissions against its authorized tasks. Use for a requ - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
ai-asset-scanner
ai-asset-scanner
### ai-asset-scanner - Discover and review AI assets in a supplied repository or exported inventory, including agents, model dependencies, prompts, MCP integration - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
browser-agent-security
browser-agent-security
### browser-agent-security - Review agents that control a browser or GUI (clicking, typing, navigating, screenshotting) for prompt injection from page content, dangerous - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
multi-agent-trust-review
multi-agent-trust-review
### multi-agent-trust-review - Review systems where one agent spawns, delegates to, or consumes output from other agents or sub-agents — orchestrators, planner/worker patt - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
prompt-injection-review
prompt-injection-review
### prompt-injection-review - Review an agent application, prompt assembly, retrieved content, or supplied incident trace for prompt injection and unsafe tool effects. Us - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
secrets-egress-review
secrets-egress-review
### secrets-egress-review - Trace how AI agents and their applications can read secrets or sensitive data and send it to logs, tools, model providers, files, or network - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
tool-schema-review
tool-schema-review
### tool-schema-review - Review tool and function definitions exposed to a model — names, descriptions, parameter schemas, and return shapes — for embedded instructi - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
webhook-callback-security
webhook-callback-security
### webhook-callback-security - Review inbound webhooks and callbacks that trigger agent actions — signature verification, replay protection, payload trust, and the authori - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
skill-scanner
skill-scanner
### skill-scanner - Review agent skill folders, archives, repository references, or updates before installation for instruction abuse, executable behavior, perm - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
agent-monitoring-review
agent-monitoring-review
### agent-monitoring-review - Review supplied agent telemetry, hook configuration, collector code, and event exports to assess observation coverage, provenance, redaction - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
ai-security
ai-security
### ai-security - Assess the security of an AI application, LLM agent, or RAG workflow using source review and scoped testing of instruction boundaries, tool - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
agent-plugin-marketplace-review
agent-plugin-marketplace-review
### agent-plugin-marketplace-review - Review a plugin, extension, or marketplace listing before bulk or organization-wide install — publisher identity and history, permission req - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
agent-network-segmentation
agent-network-segmentation
### agent-network-segmentation - Review network reachability for an agent's execution environment — egress allow-lists, internal service and metadata-endpoint exposure, DNS - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
agent-web-security
agent-web-security
### agent-web-security - Review agent-facing web interfaces, generated output rendering, and tool/API integrations for unsafe content handling, cross-user access, se - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
cloud-agent-security
cloud-agent-security
### cloud-agent-security - Review supplied cloud deployment, IAM, workload identity, network, and logging configuration for AI agents and tool services. Trace effectiv - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
agent-transport-security
agent-transport-security
### agent-transport-security - Review TLS, peer validation, credential forwarding, token verification, and cryptographic configuration protecting AI-provider, MCP, agent-c - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
api-auth-security
api-auth-security
### api-auth-security - Review API authentication and authorization used by AI agents, tools, and application backends. Trace caller identity, tenant and object acc - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
cicd-agent-security
cicd-agent-security
### cicd-agent-security - Review CI/CD workflows that run AI agents, install agent tooling, or publish their changes. Trace untrusted triggers, code checkout, shell i - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
agent-incident-response
agent-incident-response
### agent-incident-response - Triage a suspected AI agent security incident from supplied logs, repository evidence, configuration, and timelines. Preserve evidence, dist - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
container-sandbox-security
container-sandbox-security
### container-sandbox-security - Review supplied Docker, Compose, Kubernetes, and agent sandbox configuration for host exposure, privilege, writable mounts, network reach, a - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
llm-output-handling
llm-output-handling
### llm-output-handling - Review how generated model output is rendered, executed, or forwarded downstream — HTML/markdown rendering, generated code execution, genera - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
security-assessment
security-assessment
### security-assessment - Coordinate a scoped security assessment across AI agents, applications, agent infrastructure, and supplied evidence. Route work to relevant - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
dependency-supply-chain
dependency-supply-chain
### dependency-supply-chain - Review dependency changes and executable supply-chain inputs used by AI agents, skills, MCP servers, and applications. Inspect manifests, lo - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
mcp-scanner
mcp-scanner
### mcp-scanner - Scan MCP configurations, server source, package references, and supplied tool manifests before connection or after updates. Review executabl - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
security-reporting
security-reporting
### security-reporting - Review and consolidate security findings into a reproducible, redacted assessment report with calibrated severity, confidence, remediation, - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
data-retention-privacy-review
data-retention-privacy-review
### data-retention-privacy-review - Review what agent transcripts, tool arguments, and outputs get retained, for how long, and who can access them — retention windows, deletion - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
rag-memory-security
rag-memory-security
### rag-memory-security - Review retrieval-augmented generation and agent memory pipelines for cross-user disclosure, poisoned context, unsafe persistence, provenance - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
model-artifact-scanner
model-artifact-scanner
### model-artifact-scanner - Statically review supplied model packages, checkpoints, adapters, tokenizer assets, and loader configuration for unsafe deserialization, exe - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
training-data-security
training-data-security
### training-data-security - Review datasets and pipelines used for fine-tuning, embedding, or few-shot example curation for provenance, poisoning, label-flipping, embed - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.