← ClaudeAtlas

catpilot-security-corelisted

Catpilot's universal AI-coding-agent security baseline: advisory guardrails across nine components: cloud CLI mutations, database state changes, local CLI destruction, Docker container builds, hardcoded secrets, secrets management, supply-chain integrity, PII / test-data hygiene, and language-agnostic secure-coding patterns (SQL injection, command injection, XSS, path traversal, insecure deserialization, eval-class APIs, SSRF). Intended to apply on every code generation, file write, and shell command in a host that has loaded it. Born from real production incidents. Guidance the agent reads, not a runtime control.
catpilotai/catpilot-ai-guardrails · ★ 2 · AI & Automation · score 78
Install: claude install-skill catpilotai/catpilot-ai-guardrails
# Catpilot Security Core Catpilot's universal security baseline for AI coding agents, intended to apply on every file write, diff review, and shell command the agent is about to run, regardless of language or framework, whenever the host has loaded this skill. It is advice the agent reads: installing this bundle is not activation, and an instruction the agent has read is not an enforced control. The repository's protection contract explains the difference between advice, coaching, and enforcement. This file is deliberately short. Each component below names its reference file, states when it applies, and lists the rules that always hold. Do not answer from this file alone: before acting in a component's area (a cloud command that changes infrastructure, a database migration or data change, a Dockerfile, a dependency change, anything that handles a secret or real personal data, or code in the language-baseline patterns), read the named reference file with your file-reading tool and follow it. The examples, the remediation steps, and the detection patterns live there, and so do the facts that decide whether a command is safe. Component IDs match the `catpilot-components` entry in the frontmatter and the `bundle.components` list in `catpilot.json` next to this file, so a finding can be mapped back to a specific source skill (and to its severity, version, and control mappings). This bundle is generated deterministically from `src/skills/core/<id>/SKILL.md` by `tools/bundle.py`