Testing agent tool abuse
Skill casioreview20-glitch/forge-os/skills-v2/stable/testing-agent-tool-abuse
Use when verify that untrusted prompts, retrieved content, and agent outputs cannot exceed tool authority or bypass human decisions, especially when can content from a file or webpage cause a privileged call?.From its SKILL.md
npx -y skills add casioreview20-glitch/forge-os --skill testing-agent-tool-abuseAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 10 stars10 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its file declares
Copied from the file, not written here
The file declares its own license as MIT. That is the author’s claim about this one file, and it is not the same thing as the license GitHub reports for the repository, which is listed with the other numbers below.
SKILL.md
0.9 KB, 89 tokens by cl100k_base, as published. Nobody here has run it
Testing Agent Tool Abuse
Core principle
Verify that untrusted prompts, retrieved content, and agent outputs cannot exceed tool authority or bypass human decisions. Activate only when the typed entry conditions are present; stop rather than inventing a missing tool, decision, or proof.
When not to use
- a model with no tool access
- ordinary input validation unrelated to agent authority
Load only the sections selected by the RoutePlan.
What ships with it: 6 files
10.3 KB alongside SKILL.md
sections/
- decision-tables.md346 B
- examples.md331 B
- failure-modes.md259 B
- procedure.md874 B
- verification.md351 B
- manifest.json8.1 KB