catpilot-security-corelisted
Install: claude install-skill catpilotai/catpilot-ai-guardrails
# Catpilot Security Core
Catpilot's universal security baseline for AI coding agents, intended to
apply on every file write, diff review, and shell command the agent is about
to run, regardless of language or framework, whenever the host has loaded
this skill. It is advice the agent reads: installing this bundle is not
activation, and an instruction the agent has read is not an enforced
control. The repository's protection contract explains the difference
between advice, coaching, and enforcement.
This file is deliberately short. Each component below names its reference
file, states when it applies, and lists the rules that always hold. Do not
answer from this file alone: before acting in a component's area (a cloud
command that changes infrastructure, a database migration or data change, a
Dockerfile, a dependency change, anything that handles a secret or real
personal data, or code in the language-baseline patterns), read the named
reference file with your file-reading tool and follow it. The examples, the
remediation steps, and the detection patterns live there, and so do the
facts that decide whether a command is safe. Component IDs match the `catpilot-components` entry in the frontmatter and
the `bundle.components` list in `catpilot.json` next to this file, so a
finding can be mapped back to a specific source skill (and to its severity,
version, and control mappings).
This bundle is generated deterministically from
`src/skills/core/<id>/SKILL.md` by `tools/bundle.py`