Below is the output of listing my agent skills, MCP servers and extensions, plus their manifests.<br/><br/>Build me a table: name, source (registry, GitHub repo, hand-written), version or commit pinned yes/no, last updated, and whether it is fetched at runtime or installed locally.<br/><br/>Flag every row that is fetched at runtime and not pinned - those are the ones whose behaviour can change without me doing anything.<br/><br/>INSTALLED:<br/>[paste]
Here are the contents of my installed agent skills and MCP server configs.<br/><br/>Extract every domain, URL and network endpoint referenced anywhere in them.<br/><br/>Sort into: domains I would expect (the vendor, well-known registries, my own infrastructure), and domains that look like examples, placeholders or leftovers from a tutorial.<br/><br/>For the second list, tell me what would happen if someone registered each one - what the skill would fetch and what credentials it would carry.<br/><br/>CONFIGS:<br/>[paste]
Below are the config files my agent reads, including .git/config for repositories it opens.<br/><br/>List every setting in any of them that can cause a command to be executed - Git's core.fsmonitor, core.hooksPath and attr.tree, npm scripts, direnv, editor tasks, pre-commit hooks, anything else you identify.<br/><br/>For each: does my agent read this file, would it trigger without approval, and what is the one-line way to disable it globally?<br/><br/>CONFIGS:<br/>[paste]
For each agent skill below, work out what I can actually verify about its origin: who published it, whether the repository is the one the registry claims, when it was last changed, how many people maintain it, and whether the published artefact matches the source.<br/><br/>Rank by how much I am trusting versus how much I can verify.<br/><br/>Be explicit where the answer is "cannot be determined from what you have given me" rather than guessing.<br/><br/>SKILLS:<br/>[paste]
Given the skills and servers inventoried above, produce the minimal list of domains my agent genuinely needs to reach for them to function.<br/><br/>Then write me the DNS allowlist and HTTP proxy rules that permit exactly those and nothing else, for my environment below.<br/><br/>For each domain on the list, say which skill needs it and what breaks without it - I want to be able to remove entries later and know the consequence.<br/><br/>ENVIRONMENT:<br/>[paste]
From the full inventory, recommend which skills and servers to uninstall.<br/><br/>For each removal candidate give: how often I appear to use it, what it can reach, what it would cost me to lose it, and a replacement if one exists.<br/><br/>Bias toward removal. An unused skill with network access is pure risk with no offsetting benefit, and I would rather cut five things than add a control.<br/><br/>INVENTORY AND USAGE:<br/>[paste]