Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/ethonik/agentguard/agentguardnpx skills add Ethonik/agentguard --skill agentguardgit clone --depth 1 https://github.com/Ethonik/agentguardWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00189 | $0.02842 |
| Opus 5 | $0.00095 | $0.01421 |
| Sonnet 5 | $0.00038 | $0.00568 |
| Haiku 4.5 | $0.00019 | $0.00284 |
Grade A, and why
agentguard scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 178 lines — stays where its author put it; the contents beside it link to each section on GitHub.
/agentguard
Skill de seguridad para aplicaciones agénticas: cualquier herramienta que use LLMs y agentes como componentes (llamadas a modelos, tool-calling, memoria/RAG, MCP, orquestación multi-agente). Hace dos cosas:
review— audita código/diseño existente y produce un informe de hallazgos mapeados a OWASP.design— asesora antes de codificar: threat model + checklist seguro-por-diseño.
Todo se ancla a tres marcos (los IDs y términos van en inglés):
- OWASP Top 10 for Agentic Applications 2026 —
ASI01–ASI10. - OWASP Top 10 for LLM Applications 2025 —
LLM01–LLM10. - CWE (MITRE) — clase de debilidad de cada hallazgo (
CWE-1427,CWE-1426,CWE-78, …), con las mitigaciones oficiales de MITRE. Verreferences/cwe-agentic-llm-2026.md.
Uso
/agentguard # modo auto: detecta contexto y elige review o design
/agentguard review # audita el directorio actual
/agentguard review <path> # audita un path/proyecto específico
/agentguard review --quick # solo scripts (detect + scan), sin lectura profunda
/agentguard design # asesoría de diseño interactiva
/agentguard design "<idea>" # asesoría a partir de una descripción de arquitectura
/agentguard explain ASI06 # explica una amenaza concreta (ASI0x, LLM0x o CWE-nnnn)
/agentguard --help # imprime esta sección de Uso y termina
Qué debes hacer al invocarte
Si el usuario invoca /agentguard --help o -h (sin otros argumentos): imprime el bloque
## Uso de arriba verbatim y termina. No escanees, no ejecutes scripts.
Si el primer argumento es explain seguido de un ID (ASI0x / LLM0x / CWE-nnnn): lee la entrada
correspondiente en references/owasp-agentic-asi-2026.md, references/owasp-llm-top10-2025.md o
references/cwe-agentic-llm-2026.md y explícala en español (qué es, señales, mitigaciones, ejemplo
real / CWE relacionados). Termina.
Ruta de scripts: los scripts viven junto a este archivo, en scripts/. Resuélvelos relativo a la
ubicación de SKILL.md (p. ej. <skill_dir>/scripts/detect_stack.py). Corren con python3 sin
dependencias externas.
What ships with it
14 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- references/cwe-agentic-llm-2026.md 9.6 KB
- references/frameworks-map.md 2.8 KB
- references/owasp-agentic-asi-2026.md 11 KB
- references/owasp-llm-top10-2025.md 5.9 KB
- references/patterns-identity-privilege.md 3.3 KB
- references/patterns-memory-context.md 2.2 KB
- references/patterns-multiagent.md 3.0 KB
- references/patterns-prompt-injection.md 2.5 KB
- references/patterns-tool-use.md 3.5 KB
- references/report-template.md 2.1 KB
- references/secure-design-checklist.md 4.1 KB
- references/threat-model-template.md 2.1 KB
- scripts/detect_stack.py 8.8 KB runs code
- scripts/scan_agentic_patterns.py 8.8 KB runs code
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 178 lines · 189 tokens per session scan A 82c989b7d27b
agentguard is a skill published in the GitHub repository Ethonik/agentguard (2 stars, last pushed 1mo ago), licensed MIT. It adds 189 tokens to every session and 2,842 once invoked, about $0.0009 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
mcporter
List, auth, and call MCP servers/tools from the terminal.
agent-messaging
Send and receive cryptographically signed messages between AI agents using the Agent Messaging Protocol (AMP). Use when the user asks to "send a message to an agent", "check agent inbox", "message another agent", "reply to a message", "notify an agent", or any inter-agent communication task.
📝 任务完成后归档
重要提醒: 每次完成复杂调试或开发任务后,主动执行此流程! 将学到的经验归档为 skill,供以后参考。不要等用户提醒。.
oracle
Best practices for using the oracle CLI (prompt + file bundling, engines, sessions, and file attachment patterns).
agent-mode
Unified tool for managing agent LLM modes (add, remove, update, list, switch).
agento11y-prod-setup
Sets up production evaluation and guardrails for a DEPLOYED AI agent in Grafana Agent Observability, grounded in the agent's own code and its real ingested traffic. The judgment layer on top of the agento11y skill: it reads the agent's source (system prompt, tools, entrypoint) AND samples its live traffic via gcx…