wave-ctx-security

A set of security rules for an agent system that controls tool access, checks inputs and paths, and isolates commands. It covers threats such as prompt injection, path traversal, unsafe symbolic links, and misleading Unicode characters.

In plain words
What is it for?
It is for enforcing permissions, sanitizing prompts, validating file paths, rejecting unsafe links and lookalike characters, isolating processes, and removing credentials from audit logs.
Why use it?
It reduces the risk that hostile input or a malicious path causes the agent to access forbidden files or run unsafe commands. Deny rules and path checks are applied before access is allowed.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/re-cinq/wave/wave-ctx-security
Any agent
npx skills add re-cinq/wave --skill wave-ctx-security
Clone the repo
git clone --depth 1 https://github.com/re-cinq/wave

Made for: Claude Code, Codex.

Per session 77 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,620 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00077 $0.01620
Opus 5 $0.00039 $0.00810
Sonnet 5 $0.00015 $0.00324
Haiku 4.5 $0.00008 $0.00162

Measured 3d ago against content hash 21998458f982, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

wave-ctx-security scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.agents/skills/wave-ctx-security/SKILL.md · 97 lines

How it starts

The opening of the file, as written. The whole thing — 97 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Security Context

Three-layer defense system — permission enforcement (deny-first tool access control), input sanitization (prompt injection detection, risk scoring), path validation (traversal prevention, symlink rejection, Unicode homograph detection), sandbox isolation (Docker with full hardening, bubblewrap via Nix), credential scrubbing in audit logs, and curated subprocess environments.

Invariants

  • Deny patterns ALWAYS take precedence over allow patterns — deny rules checked first, match blocks regardless of allow rules
  • Path traversal sequences always rejected — checks .., ./, ../, ..\, URL-encoded variants (%2e%2e, %252e%252e, ..%2f, ..%5c)
  • Paths must be within approved directories — resolved to absolute, checked via filepath.Rel, relative path must not start with '..'
  • Symlinks rejected by default — every path component checked via os.Lstat for os.ModeSymlink when AllowSymlinks is false
  • Unicode homograph attacks detected and blocked — UTF-7 sequences rejected, mixed confusable scripts (Latin+Cyrillic, Latin+Greek, Latin+Arabic, Latin+Hebrew) rejected; CJK intentionally allowed
  • Path length must not exceed MaxPathLength (default 255)
  • Prompt injection detection enabled by default in strict (MustPass) mode — seven regex patterns detect injection attempts
  • Input length capped at MaxInputLength (default 10000 characters) — excess truncated
  • Schema content size must not exceed ContentSizeLimit (default 1MB) — hard error, not truncation
  • Script tags, event handlers, and javascript: URLs always stripped from schema content
  • TodoWrite always injected into the deny list for every adapter invocation
  • Docker containers always run with --read-only, --cap-drop=ALL, --security-opt=no-new-privileges, --network=none
  • Docker containers get tmpfs mounts with nosuid,nodev for /tmp, /var/run, /home/wave
  • Artifact directories mounted read-only in Docker; output and workspace directories read-write
  • Docker UID/GID mapping defaults to host user — prevents root execution inside container
  • All logged output scrubbed for credential patterns before writing to disk — 8 patterns: API_KEY, TOKEN, SECRET, PASSWORD, CREDENTIAL, AUTH, PRIVATE_KEY, ACCESS_KEY
  • Credential scrubbing applies to ALL log methods — tool calls, file ops, step start/end, error messages
  • DebugTracer writes are thread-safe — sync.Mutex protects file handle, verified with 50-goroutine concurrency test
  • Adapter subprocesses receive curated environment, not full host environment — only HOME, PATH, TERM, TMPDIR=/tmp plus whitelisted vars
  • Claude Code telemetry suppressed — DISABLE_TELEMETRY, DISABLE_ERROR_REPORTING, CLAUDE_CODE_DISABLE_FEEDBACK_SURVEY, DISABLE_BUG_COMMAND
  • Claude Code always runs with --dangerously-skip-permissions — Wave enforces permissions via agent frontmatter instead
  • All embedded personas, pipelines, and prompts scanned for unsafe CLI interpolation patterns — prevents shell injection via double-quoted variable expansion
  • MaxPathLength, MaxInputLength, and ContentSizeLimit must all be positive — non-positive values produce non-retryable SecurityValidationError
  • AllowSymlinks defaults to false, AllowUnknownPersonas defaults to false, ValidatePersonaReferences defaults to true
  • Risk score capped at 100 — scores >=50 considered high risk
  • Security errors are structured with retryability metadata — path traversal and config errors non-retryable; injection and input errors retryable

Read the full file on GitHub · 97 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 3d ago First seen · 97 lines · 77 tokens per session scan A 21998458f982

Subscribe to this mod's changes

wave-ctx-security is a skill published in the GitHub repository re-cinq/wave (20 stars, last pushed 4mo ago), licensed MIT. It adds 77 tokens to every session and 1,620 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

coordinate-agents

Route Codex-native multi-agent orchestration in a Git repository through a local-first, recoverable Agent Bus. Use for role-based planning, task execution, review, recovery, adapters, and human-gated release workflows. The plugin supports Codex CLI, Google Antigravity CLI, Claude, and other configured coding agents.…

hogancv/coordinate-agents · 87 tokens

coordinate-task

Run a Coordinate Agents Task from requirement clarification through planning, implementation, review, and the human release gate. Hide Agent Bus transport details behind the durable Task API.

hogancv/coordinate-agents · 35 tokens

coordinate-recover

Diagnose and safely resume Coordinate Agents Tasks after executable failure, non-zero exit, timeout, stale claim, processing message, or Implementer ERROR. Recovery is explicit and never an automatic retry loop.

hogancv/coordinate-agents · 43 tokens

coordinate-setup

Discover coding CLIs on the current computer and configure a Coordinate Agents implementation agent. Use for setup, executable checks, registered agents, user-level configuration, and project-over-user precedence.

hogancv/coordinate-agents · 40 tokens

coordinate-review

Review a Coordinate Agents implementation as the Codex Reviewer. Verify the real commit, diff, tests, validation evidence, and specification without modifying the Implementer's product code.

hogancv/coordinate-agents · 36 tokens

api-contracts

Enforce API contract governance, strict backward compatibility, schema validation, and standardized RFC 7807 error responses.

rafaelghif/antigravity-agents · 26 tokens