agent-safety-preflight
Generate a local repository risk receipt before Claude Code or other AI-agent edits. Use when the user asks to prepare a repository for agent changes, check for risky hooks or credential-writing automation, or run the /agent-preflight command.
Install / Use
npx skills add jeremylongshore/tons-of-skills-marketplace --skill agent-safety-preflightInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
AutomationSupported Platforms
Our assessment of agent-safety-preflight
agent-safety-preflight scores 87/100 on our quality scale, 1233rd of 2,250 Automation skills we index.
Its SKILL.md is 4.7 KB long, well organised into 12 sections with 1 code example: a solid amount of guidance for an agent.
With 2,785 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 5 days ago, so agent-safety-preflight is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
agent-safety-preflight compared with similar skills
All 4 of these similar skills score higher than agent-safety-preflight; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| agent-safety-preflight (this skill)by jeremylongshore | 87 | 2.8k | 5d ago | SKILL.md |
| Agent-Reachby Panniantong | 100 | 86.1k | 14d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.1k | today | CLAUDE.md |
| rufloby ruvnet | 100 | 73.5k | today | CLAUDE.md |
| crawl4aiby unclecode | 100 | 84.5k | 4d ago | MCP Server |
Frequently asked questions
- How do I install agent-safety-preflight?
- Run
npx skills add jeremylongshore/tons-of-skills-marketplace --skill agent-safety-preflight. The install tabs above show the steps for each supported agent. - Which AI agents does agent-safety-preflight work with?
- It is written for Claude Code, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is agent-safety-preflight safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is agent-safety-preflight still maintained?
- The repository was last updated 5 days ago, so agent-safety-preflight is actively maintained.
Skill content
View source on GitHubname: agent-safety-preflight description: | Generate a local repository risk receipt before Claude Code or other AI-agent edits. Use when the user asks to prepare a repository for agent changes, check for risky hooks or credential-writing automation, or run the /agent-preflight command. Trigger with "run agent preflight", "check this repo before agent edits", or "/agent-preflight". argument-hint: "[repo-path]" allowed-tools: Read, Bash(git:), Bash(python3:) version: 1.2.0 author: Signal Loom Works 194151508+el-zachariah@users.noreply.github.com license: MIT compatibility: Designed for Claude Code tags:
- security
- agent-safety
- claude-code
- preflight
Agent Safety Preflight
Overview
Agent Safety Preflight helps Claude inspect a local repository before making AI-agent-assisted edits. It produces a compact Green, Yellow, or Red risk receipt from local files only, with special attention to destructive shell patterns, credential-writing automation, agent authority surfaces, uncommitted changes, and unavailable git state.
The skill pairs with the /agent-preflight command in this plugin. Prefer the bundled lightweight scanner when it is available from a trusted Claude install root, then explain the decision and next safe action before editing.
Prerequisites
- A local repository or workspace path to inspect.
- Python 3 available for the bundled
agent_preflight_lite.pyscanner. - Git available when the workspace is a git repository.
- Permission to read the target workspace locally.
Do not send source, secrets, tokens, private repository contents, payment credentials, or environment variables to external services while using this skill.
Instructions
- Confirm the target repository path. Use the current workspace unless the user supplied a path.
- Use
Readonly for local documentation or configuration files that explain the workspace; do not copy private source into the response. - Run
/agent-preflightwhen the command is installed, or invoke the bundled scanner from a trusted Claude install root. - If the scanner is unavailable, apply the same manual decision rules: destructive commands, credential-writing automation, risky agent authority, git state, and high-risk shell or network install chains.
- Classify the workspace as Green, Yellow, or Red.
- Report the decision, evidence, and next safe action before making edits.
- For Yellow results, ask for a checkpoint or narrower scope before broad edits.
- For Red results, stop and request human review before changing files.
Output
Return a short receipt in Markdown that is safe to paste into the local work log or pull request notes:
## Agent Safety Preflight Receipt
- Decision: Green | Yellow | Red
- Repository: <path>
- Git state: clean | dirty | unavailable
- Risk buckets: <bullets>
- Evidence: <file/path markers>
- Next safe action: proceed | checkpoint | stop
Error Handling
- If the scanner cannot be found from a trusted install root, say that the automated scanner did not run and use the manual rules.
- If git status is unavailable, classify the workspace as Yellow rather than Green.
- If a file cannot be decoded, scan the readable prefix with tolerant UTF-8 decoding and include a note if relevant evidence may be incomplete.
- If a destructive or credential-writing marker appears in an agent-controlled path, classify the workspace as Red and stop.
- If the workspace is too large for a full pass, inspect high-signal paths first:
.claude/,.cursor/,.github/, shell scripts, JSON/YAML/TOML config, package manifests, and environment files.
Examples
Example 1: Clean repo before routine edits
User request: "Run a preflight before you update this README."
The skill runs the scanner, sees a clean git state and no high-risk automation markers, then returns Green with the repository path and evidence summary.
Example 2: Agent hooks present
User request: "Check this repo before the agent refactor."
The skill detects agent hook configuration or broad tool permissions, returns Yellow, and recommends a checkpoint or narrower edit scope before continuing.
Example 3: Destructive automation found
User request: "Start editing this generated-project repo."
The skill finds a destructive recursive delete pattern in an automation file, returns Red, and stops until a human reviews the workflow.
Resources
- Command:
plugins/security/agent-safety-preflight/commands/agent-preflight.md - Scanner:
plugins/security/agent-safety-preflight/scripts/agent_preflight_lite.py - Decision-rule reference:
references/decision-rules.md - Public source workflow: https://github.com/el-zachariah/ai-agent-safety-starter-pack
- Claude Code plugin reference: https://code.claude.com/docs/en/plugins
Related Skills
Agent-Reach
86.1kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.1kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
ruflo
73.5k🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated
crawl4ai
84.5kOpen-source web crawler and scraper for LLMs and AI agents: any website into clean, LLM-ready Markdown. Run it yourself, or use Crawl4AI Cloud with one key.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
