MON, SEPTEMBER 28, 2026
Independent · In‑Depth · Practitioner‑Tested
Claude Productivity

Six Prompts to Audit What Your Agent Tooling Trusts

Two findings in four weeks from the same researcher: a repository's own Git config can name a command your coding agent executes, and 349 agent skills reference domains nobody ever registered. Both have the same shape - the dangerous thing is configuration something else controls, not code you reviewed. These six prompts map what your agent setup trusts and where that trust is misplaced.

⌨️ 6 prompts 🕐 Updated Sep 28, 2026
💡 How to use these prompts: Replace everything in [BRACKETS] with your specific details before sending. Click Copy to copy any prompt to your clipboard instantly.
1
Inventory What Is Actually Installed
Most people cannot name everything their agent has loaded. Start with the list.
Below is the output of listing my agent skills, MCP servers and extensions, plus their manifests.<br/><br/>Build me a table: name, source (registry, GitHub repo, hand-written), version or commit pinned yes/no, last updated, and whether it is fetched at runtime or installed locally.<br/><br/>Flag every row that is fetched at runtime and not pinned - those are the ones whose behaviour can change without me doing anything.<br/><br/>INSTALLED:<br/>[paste]
2
Find Every Domain the Tooling Reaches
349 skills were found referencing unregistered placeholder domains. Check yours before someone else does.
Here are the contents of my installed agent skills and MCP server configs.<br/><br/>Extract every domain, URL and network endpoint referenced anywhere in them.<br/><br/>Sort into: domains I would expect (the vendor, well-known registries, my own infrastructure), and domains that look like examples, placeholders or leftovers from a tutorial.<br/><br/>For the second list, tell me what would happen if someone registered each one - what the skill would fetch and what credentials it would carry.<br/><br/>CONFIGS:<br/>[paste]
3
Audit Config-Driven Execution
GitSpawn worked because nobody thinks of a config file as executable. Several of them are.
Below are the config files my agent reads, including .git/config for repositories it opens.<br/><br/>List every setting in any of them that can cause a command to be executed - Git's core.fsmonitor, core.hooksPath and attr.tree, npm scripts, direnv, editor tasks, pre-commit hooks, anything else you identify.<br/><br/>For each: does my agent read this file, would it trigger without approval, and what is the one-line way to disable it globally?<br/><br/>CONFIGS:<br/>[paste]
4
Trace a Skill to Its Author
Provenance is the question package registries taught us to ask and agent skill ecosystems have not yet learned.
For each agent skill below, work out what I can actually verify about its origin: who published it, whether the repository is the one the registry claims, when it was last changed, how many people maintain it, and whether the published artefact matches the source.<br/><br/>Rank by how much I am trusting versus how much I can verify.<br/><br/>Be explicit where the answer is "cannot be determined from what you have given me" rather than guessing.<br/><br/>SKILLS:<br/>[paste]
5
Write the Egress Allowlist
An allowlist turns a hijacked placeholder domain into a failed lookup. It is the single control that covers both findings.
Given the skills and servers inventoried above, produce the minimal list of domains my agent genuinely needs to reach for them to function.<br/><br/>Then write me the DNS allowlist and HTTP proxy rules that permit exactly those and nothing else, for my environment below.<br/><br/>For each domain on the list, say which skill needs it and what breaks without it - I want to be able to remove entries later and know the consequence.<br/><br/>ENVIRONMENT:<br/>[paste]
6
Decide What to Remove
The cheapest security control is having less installed. Most agent setups accumulate skills nobody has used in months.
From the full inventory, recommend which skills and servers to uninstall.<br/><br/>For each removal candidate give: how often I appear to use it, what it can reach, what it would cost me to lose it, and a replacement if one exists.<br/><br/>Bias toward removal. An unused skill with network access is pure risk with no offsetting benefit, and I would rather cut five things than add a control.<br/><br/>INVENTORY AND USAGE:<br/>[paste]