immune-checklisted
Install: claude install-skill thdelmas/immune-check
# Immune Check — scan before anything leaves the body
A boundary defense. Before any artifact crosses out of the body — into a public repo, an external service, a release, someone else's inbox — this is the reflex that scans it for foreign or dangerous material, so an infection never spreads in the first place. It is far cheaper to never leak than to scrub a leak after the fact.
This is the **immune** organ of an agent's nervous system: it distinguishes *self* (safe to expose) from *non-self* (must not cross the membrane), responds proportionally, and **remembers** every antigen so the next scan is faster.
## What counts as an outbound boundary
Any moment an artifact leaves your control and becomes hard to recall:
- Making a repo or file **public** (the highest-stakes membrane — public is forever, even after deletion).
- **Pushing** a commit, **cutting** a release, opening a PR to an upstream you don't own.
- **Sending** a payload to an external API, a webhook, a paste service, a third-party tool.
- Attaching files to a **message** going outside the trusted circle.
If it can be un-done with a local edit, it's still inside the body — no scan needed. If recalling it means asking someone else to forget, scan first.
## Stack-agnostic by design
The scan adapts to whatever you have. Detect a scanner in this order and use the first available; if none, fall back to the built-in pattern pass:
1. **Argus** — `argus` on PATH (the reference organ this skill was modeled on).
2. *