Agent Safety & Verification Bundle
Five local, read-only safety auditors for the places agent-assisted development goes wrong. Test your Claude Code guardrails and prompt-injection defenses (Guardrail Doctor), force the agent to verify its own code before it claims success (AI Code Verification Gate), scaffold and review MCP servers with safe tool definitions and confirmation gates (MCP Server Starter & Safety Kit), tighten GitHub Actions permissions and unsafe pull_request_target usage (GitHub Actions Permission Hardener), and vet dependency changes for supply-chain risk before you install (Package Supply-Chain Sentinel). For developers and teams shipping AI-agent and CI-driven work who want to catch the guardrail gap, the unverified change, the over-permissioned workflow, and the malicious package before they bite, not after the incident report. Every tool flags what to fix with severity and remediation, and never touches your live systems without confirmation.
You save $30 vs buying individually.
What's included (5 skills)
Penetration-test your Claude Code agent's guardrails before you deploy. Throws prompt-injection payloads, shell-chaining, and path-traversal attempts at your PreToolUse/PostToolUse hooks and sensitive-file protections, then returns a pass/fail report on 10+ attack vectors with copy-paste remediation for every gap.
One-line summary description Stop your agent from claiming "done" before it's proven. A verification gate that classifies each change by risk (payment, auth, database, user-facing), picks the tests that actually cover it, demands evidence, maps regression risk, and outputs an honest pass/fail report. Turns "looks good to me" into "here's what I ran, and here's what's still unverified."
Scaffold and audit secure MCP servers with input schemas, confirmation gates, and safety-first tool definitions.
Audit and harden GitHub Actions workflows against overbroad permissions, secrets exposure, and supply-chain risks.
Vet dependency changes for supply-chain risk before you install, commit, or release. Scans package and lockfile diffs for install-time lifecycle scripts, non-registry sources, suspicious download commands, typosquatting, and floating versions, across npm, pnpm, yarn, pip, uv, and poetry. Flags what to review with evidence. No install required.