Threat-model agentic tooling — MCP/tool abuse, hook/prompt injection, remote control surfaces, and secret leakage. Use during security reviews or when adding features that expose the system to AI agents or remote callers.
설치
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
Threat-model agentic tooling — MCP/tool abuse, hook/prompt injection, remote control surfaces, and secret leakage. Use during security reviews or when adding features that expose the system to AI agents or remote callers.
Threat modeling (agentic tools)
Use this skill when
Security reviews, or new features touching MCP servers, tools, hooks, or any remote-control surface
Writing or updating security docs
Running /security-review or reviewing compact MCP dispatch actions
Procedure
Read .agent/SAFETY.md and backend docs/technical/MCP_SEARCH_DISPATCH.md.
Enumerate assets: secrets/tokens, credentials, workspace files, agent sessions, PostgreSQL data,
Electron IPC surfaces, any data the tools can read or mutate.