← ClaudeAtlas

ref-sp-agents-securitylisted

Reference guidance for agent security policy, protected file access, exclusion sync, and multi-client enforcement. Use when: modifying a policy source file, updating the sync workflow, reviewing generated restriction files, or changing how agents are prevented from reading sensitive files.
swiftpostlabs/agentic-tools · ★ 0 · AI & Automation · score 73
Install: claude install-skill swiftpostlabs/agentic-tools
# Agents Security ## Purpose Define how agent clients are prevented from reading sensitive files, how noisy or generated files are excluded from context, and how the policy is synchronized across agent-specific configurations. ## Values - Prefer simplicity over cleverness. - Prefer maintainability over short-term convenience. - Keep policy synchronization deterministic and easy to audit. - Keep the source of truth explicit. - Make enforcement boundaries and limitations visible. ## When to use this skill - Adding or modifying protected or excluded file patterns. - Updating the sync script or sync workflow. - Reviewing generated restriction files. - Reviewing AI security configuration across clients. - Adopting the policy system in another repository. ## Scope boundaries This skill owns the **agent file-access policy**: which files an agent may read, how exclusions are generated, and how each client enforces them. - `ref-sp-agents-policy` — this repo's concrete implementation of that model: the `.agents/config.json` policy section, the sync command, and the generated vendor outputs. This skill is the portable model; that one is the local machinery. - `ref-sp-db-security` — despite the similar name, an unrelated subject: protecting a *database* (privileges, encryption, auditing). Nothing to do with agent file access. - `ref-sp-dev-github-actions-ci` — workflow token scope, runner trust, and action pinning. CI hardening is a different attack surface from agent re