Use when code executes commands, installs hooks/plugins, handles untrusted input, writes outside a workspace, or crosses privilege/network boundaries.
Scanned 9/3/2026
Install to Claude Code
npx -y skills add ShugokiFable/Ultimate-AI-Starter-Bundle --skill security-boundaries --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Security Boundaries?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/shugokifable-security-boundaries)More formats (shields.io, HTML) on the badges page.
---
name: security-boundaries
description: Use when code executes commands, installs hooks/plugins, handles untrusted input, writes outside a workspace, or crosses privilege/network boundaries.
---
# Security Boundaries
## Core rule
Identify each **trust boundary** explicitly and apply **least privilege** at that boundary.
## Contract
Treat downloaded content, repository files from unknown origins, generated shell text, archive members, plugin hooks, environment variables, and user-supplied paths as **untrusted** until validated for the operation being performed.
Prefer argument arrays over shell interpolation; validate archive paths; constrain write roots; avoid privilege elevation unless required; verify signatures/hashes for bootstrapped executables when feasible; preserve provider trust prompts unless the user has explicitly opted into the exact automation being installed.
Do not disable dangerous-command approval globally to remove one setup prompt. Scope consent to the known component or one installer process.
Security checks are part of correctness: a “working” installer that can overwrite arbitrary paths or silently trust future third-party hooks is not near-perfect.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!
Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...
Ultra-compressed communication mode. Cuts token usage ~75% by speaking like caveman while keeping full technical accuracy. Supports intensity levels: lite, full (default), ultra, wenyan-lite, wenyan-full, wenyan-ultra. Use when user says "caveman mode", "talk like caveman", "use caveman", "less tokens", "be brief", or invokes /caveman. Also auto-triggers when token efficiency is requested.
Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.
**Complete production-ready guide for Google Gemini embeddings API** This skill provides comprehensive coverage of the `gemini-embedding-001` model for generating text embeddings, including SDK usage, REST API patterns, batch processing, RAG integration with Cloudflare Vectorize, and advanced use cases like semantic search and document clustering. ---
Recovers prior coding-agent session context by running `catchup <agent> --since-compact`, which extracts a clean summary of a previous Codex, Claude Code, Antigravity, OpenCode, or Pi Agent session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", or asks to recover/summarize a previous session before continuing. Do NOT use for the current conversation, git history, or any non-agent log.