Hunt vulnerabilities like an expert, not a linear software engineer: come at a target from the overlooked angle, reason by analogy and transfer proven attack mechanisms, attack the hidden assumptions and the seams between systems, drill to the mechanism, then keep it honest with proof and persistence (acceptance !=…
Audit an AI agent deployment against the CUSTODY containment framework and LASM threat model. Checks identity, input handling, supervision, traceability, operational controls, dependency management, and yield/teardown. Maps findings to NIST AI RMF, OWASP, CUSTODY pillars, and LASM layers.
Use this skill when the user is building, securing, or auditing a browser-based AI agent (Playwright, Puppeteer, Stagehand, browser-use, or custom browser automation). Triggers on requests to "secure my browser agent", "detect prompt injection in web pages", "block my agent from visiting bad URLs", "scan this page for…
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: