Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/re-cinq/wave/wave-ctx-securitynpx skills add re-cinq/wave --skill wave-ctx-securitygit clone --depth 1 https://github.com/re-cinq/waveWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00077 | $0.01620 |
| Opus 5 | $0.00039 | $0.00810 |
| Sonnet 5 | $0.00015 | $0.00324 |
| Haiku 4.5 | $0.00008 | $0.00162 |
Grade A, and why
wave-ctx-security scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 97 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Security Context
Three-layer defense system — permission enforcement (deny-first tool access control), input sanitization (prompt injection detection, risk scoring), path validation (traversal prevention, symlink rejection, Unicode homograph detection), sandbox isolation (Docker with full hardening, bubblewrap via Nix), credential scrubbing in audit logs, and curated subprocess environments.
Invariants
- Deny patterns ALWAYS take precedence over allow patterns — deny rules checked first, match blocks regardless of allow rules
- Path traversal sequences always rejected — checks .., ./, ../, ..\, URL-encoded variants (%2e%2e, %252e%252e, ..%2f, ..%5c)
- Paths must be within approved directories — resolved to absolute, checked via filepath.Rel, relative path must not start with '..'
- Symlinks rejected by default — every path component checked via os.Lstat for os.ModeSymlink when AllowSymlinks is false
- Unicode homograph attacks detected and blocked — UTF-7 sequences rejected, mixed confusable scripts (Latin+Cyrillic, Latin+Greek, Latin+Arabic, Latin+Hebrew) rejected; CJK intentionally allowed
- Path length must not exceed MaxPathLength (default 255)
- Prompt injection detection enabled by default in strict (MustPass) mode — seven regex patterns detect injection attempts
- Input length capped at MaxInputLength (default 10000 characters) — excess truncated
- Schema content size must not exceed ContentSizeLimit (default 1MB) — hard error, not truncation
- Script tags, event handlers, and javascript: URLs always stripped from schema content
- TodoWrite always injected into the deny list for every adapter invocation
- Docker containers always run with --read-only, --cap-drop=ALL, --security-opt=no-new-privileges, --network=none
- Docker containers get tmpfs mounts with nosuid,nodev for /tmp, /var/run, /home/wave
- Artifact directories mounted read-only in Docker; output and workspace directories read-write
- Docker UID/GID mapping defaults to host user — prevents root execution inside container
- All logged output scrubbed for credential patterns before writing to disk — 8 patterns: API_KEY, TOKEN, SECRET, PASSWORD, CREDENTIAL, AUTH, PRIVATE_KEY, ACCESS_KEY
- Credential scrubbing applies to ALL log methods — tool calls, file ops, step start/end, error messages
- DebugTracer writes are thread-safe — sync.Mutex protects file handle, verified with 50-goroutine concurrency test
- Adapter subprocesses receive curated environment, not full host environment — only HOME, PATH, TERM, TMPDIR=/tmp plus whitelisted vars
- Claude Code telemetry suppressed — DISABLE_TELEMETRY, DISABLE_ERROR_REPORTING, CLAUDE_CODE_DISABLE_FEEDBACK_SURVEY, DISABLE_BUG_COMMAND
- Claude Code always runs with --dangerously-skip-permissions — Wave enforces permissions via agent frontmatter instead
- All embedded personas, pipelines, and prompts scanned for unsafe CLI interpolation patterns — prevents shell injection via double-quoted variable expansion
- MaxPathLength, MaxInputLength, and ContentSizeLimit must all be positive — non-positive values produce non-retryable SecurityValidationError
- AllowSymlinks defaults to false, AllowUnknownPersonas defaults to false, ValidatePersonaReferences defaults to true
- Risk score capped at 100 — scores >=50 considered high risk
- Security errors are structured with retryability metadata — path traversal and config errors non-retryable; injection and input errors retryable
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 97 lines · 77 tokens per session scan A 21998458f982
wave-ctx-security is a skill published in the GitHub repository re-cinq/wave (20 stars, last pushed 4mo ago), licensed MIT. It adds 77 tokens to every session and 1,620 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
coordinate-agents
Route Codex-native multi-agent orchestration in a Git repository through a local-first, recoverable Agent Bus. Use for role-based planning, task execution, review, recovery, adapters, and human-gated release workflows. The plugin supports Codex CLI, Google Antigravity CLI, Claude, and other configured coding agents.…
coordinate-task
Run a Coordinate Agents Task from requirement clarification through planning, implementation, review, and the human release gate. Hide Agent Bus transport details behind the durable Task API.
coordinate-recover
Diagnose and safely resume Coordinate Agents Tasks after executable failure, non-zero exit, timeout, stale claim, processing message, or Implementer ERROR. Recovery is explicit and never an automatic retry loop.
coordinate-setup
Discover coding CLIs on the current computer and configure a Coordinate Agents implementation agent. Use for setup, executable checks, registered agents, user-level configuration, and project-over-user precedence.
coordinate-review
Review a Coordinate Agents implementation as the Codex Reviewer. Verify the real commit, diff, tests, validation evidence, and specification without modifying the Implementer's product code.
api-contracts
Enforce API contract governance, strict backward compatibility, schema validation, and standardized RFC 7807 error responses.