Add OpenClaw local and Mac mini setup skill

This commit is contained in:
Toby
2026-02-21 09:54:14 -05:00
parent 2639af6531
commit b3be11e88e
17 changed files with 672 additions and 0 deletions
+38
View File
@@ -0,0 +1,38 @@
---
name: ai-agent-security
description: Secure AI agents against prompt injection, tool abuse, and data exfiltration with defense-in-depth controls.
license: MIT
metadata:
author: devops-skills
version: "1.0"
---
# AI Agent Security
Protect agentic systems from adversarial input and unsafe tool execution.
## Threats to Model
- Prompt injection through untrusted content
- Excessive permissions on tools and APIs
- Data exfiltration via model responses
- Cross-tenant context leakage
## Security Controls
1. Isolate tool execution with strict allowlists.
2. Add policy checks before sensitive actions.
3. Limit token scope and credential lifetimes.
4. Apply output filtering for sensitive data.
5. Log every privileged tool invocation.
## Incident Readiness
- Keep immutable audit trails for prompts and tool calls.
- Build kill switches for high-risk tools.
- Run regular red-team scenarios.
## Related Skills
- [llm-app-security](../llm-app-security/) - Application-layer LLM defenses
- [threat-modeling](../operations/threat-modeling/) - Structured risk analysis
+32
View File
@@ -0,0 +1,32 @@
---
name: llm-app-security
description: Secure LLM-powered applications with input validation, output controls, tenant isolation, and abuse prevention.
license: MIT
metadata:
author: devops-skills
version: "1.0"
---
# LLM Application Security
Harden chatbots and AI features embedded in web and mobile products.
## Baseline Security Checklist
- Validate and classify all user-provided context.
- Separate system prompts from user content strictly.
- Add moderation for toxic, harmful, and policy-violating outputs.
- Enforce tenant boundaries in retrieval and memory layers.
- Rate-limit high-cost endpoints.
## Secure RAG Pattern
1. Ingest content with malware and secret scanning.
2. Tag documents by tenant and access policy.
3. Filter retrieval candidates by user authorization.
4. Add provenance metadata in final responses.
## Related Skills
- [ai-agent-security](../ai-agent-security/) - Agent-specific controls
- [sast-scanning](../scanning/sast-scanning/) - Secure coding checks