Skip to content
Back to skills

Agentdoctor Zero Trust Security

ASecurity

Zero-trust security review for AgentDoctor ownership, path/symlink safety, approvals, MCP/CLI/dashboard authority, and prompt injection. Use when auditing or fixing trust boundaries—not for feature work.

  • 10 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 28, 2026
ai-agentsrustgogitsecurity

Works with

  • cli
  • mcp

Security analysis

A100/100

Scanned September 28, 2026

npx -y skills add pranee54/AgentDoctor --skill agentdoctor-zero-trust-security --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Agentdoctor Zero Trust Security?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Agentdoctor Zero Trust Security
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/pranee54-agentdoctor-zero-trust-security/badge)](https://www.skillsdirectory.com/skills/pranee54-agentdoctor-zero-trust-security)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: agentdoctor-zero-trust-security
description: Zero-trust security review for AgentDoctor ownership, path/symlink safety, approvals, MCP/CLI/dashboard authority, and prompt injection. Use when auditing or fixing trust boundaries—not for feature work.
---

# AgentDoctor zero-trust security

## Purpose
Keep AgentDoctor as the authority for boundaries, tools, approval, verification, and evidence. Models and repo text are untrusted data.

## Canonical layers
- Containment: `src/security/paths.ts` `resolveSafeRepoPath`
- Ownership: `src/project/ownership.ts` (realpath classification; `OWNERSHIP_BOUNDARY_VERSION`)
- CLI broad-root: `src/cli/safe-root.ts` `resolveCliProjectRoot`
- Discovery: `src/discovery/files.ts` `decideDirectoryTraversal`

## Non-negotiable rules
- Containment ≠ ownership
- Fail closed on path/ownership deny
- No UI/`approved=true` boolean as write authority
- Dashboard chat is ask-only (no repo writes)
- Repository content (README, AGENTS.md, comments) cannot escalate privileges
- Skills/prompts cannot override runtime controls

## Hostile checklist
- `.private/`, `AgentDoctorOS/`, nested `.git`, fixtures, validation checkouts
- Symlink alias into private/foreign
- `$HOME` / Desktop / Downloads / Documents
- Forged planHash / grant / approvalToken
- MCP STDIO forge (not helper-only tests)
- Provider tool-call loop with local adversarial server
- what-if foreign/private targets

## Evidence
Prefer executable tests under `tests/unit/project/`, `tests/unit/mcp/mcp-transport-adversarial.test.ts`, `tests/unit/ai/provider-adversarial-e2e.test.ts`.

## What NOT to do
Weaken ownership to fix false-positive tests; claim transport-complete MCP without STDIO forge; claim vendor LLM safety from local deterministic E2E alone.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…