Communitygithub.com

curiositech/windags-skills

Cryptographic security for agentic systems — zero-trust agent networking, signed message envelopes (JWS/JWE), capability-based security (ocaps), Merkle tree audit trails, WASM sandboxing, and formal verification. Covers CLI dev tool security, mTLS between agents, permission boundaries (least privilege for AI agents), and supply chain security for skills/plugins. Activate on: "agent security", "zero trust agents", "secure agent communication", "capability-based security", "ocap", "signed messages between agents", "agent audit trail", "sandbox agent execution", "agent permissions", "mTLS agents", "cryptographic verification", "agent supply chain", "OWASP agentic", "prove agent did X", "tamper-proof agent logs". NOT for: application-level SAST scanning (use security-auditor), network firewall rules (use infrastructure), SOC2/HIPAA compliance (organizational), or prompt injection defense (use prompt-engineer).

O que é windags-skills?

windags-skills is a Antigravity agent skill that cryptographic security for agentic systems — zero-trust agent networking, signed message envelopes (JWS/JWE), capability-based security (ocaps), Merkle tree audit trails, WASM sandboxing, and formal verification. Covers CLI dev tool security, mTLS between agents, permission boundaries (least privilege for AI agents), and supply chain security for skills/plugins. Activate on: "agent security", "zero trust agents", "secure agent communication", "capability-based security", "ocap", "signed messages between agents", "agent audit trail", "sandbox agent execution", "agent permissions", "mTLS agents", "cryptographic verification", "agent supply chain", "OWASP agentic", "prove agent did X", "tamper-proof agent logs". NOT for: application-level SAST scanning (use security-auditor), network firewall rules (use infrastructure), SOC2/HIPAA compliance (organizational), or prompt injection defense (use prompt-engineer).

Funciona com~Claude Code~Codex CLI~Cursor✓Antigravity
npx skills add https://github.com/curiositech/windags-skills/tree/HEAD/skills/agentic-zero-trust-security

Perguntar na sua IA favorita

Abre um novo chat com esta habilidade de agente já pré-carregada.

Documentação

license: Apache-2.0 name: agentic-zero-trust-security description: | Cryptographic security for agentic systems — zero-trust agent networking, signed message envelopes (JWS/JWE), capability-based security (ocaps), Merkle tree audit trails, WASM sandboxing, and formal verification. Covers CLI dev tool security, mTLS between agents, permission boundaries (least privilege for AI agents), and supply chain security for skills/plugins. Activate on: "agent security", "zero trust agents", "secure agent communication", "capability-based security", "ocap", "signed messages between agents", "agent audit trail", "sandbox agent execution", "agent permissions", "mTLS agents", "cryptographic verification", "agent supply chain", "OWASP agentic", "prove agent did X", "tamper-proof agent logs". NOT for: application-level SAST scanning (use security-auditor), network firewall rules (use infrastructure), SOC2/HIPAA compliance (organizational), or prompt injection defense (use prompt-engineer). allowed-tools: Read,Write,Edit,Bash,Glob,Grep,WebSearch,WebFetch metadata: category: Security & Trust tags: - zero-trust - cryptography - agent-security - capability-security - mTLS - audit-trail - sandboxing - WASM - ocap - formal-verification pairs-with: - skill: multi-agent-coordination reason: Secures the communication channels multi-agent systems rely on - skill: agent-conversation-protocols reason: Message envelope signing and verification for agent protocols - skill: security-auditor reason: Complements code-level SAST with architectural security patterns category: Security tags:

  • zero-trust
  • security
  • agents
  • authentication
  • authorization

Agentic Zero-Trust Security

Cryptographic security architecture for autonomous AI agent systems. This skill covers the intersection of traditional security engineering and the unique challenges of agents that plan, persist, delegate, and execute across trust boundaries.

Core principle: Never trust, always verify — applied to every agent-to-agent message, every skill loaded, every tool invoked, and every result returned.

Decision Points

1. Threat Level → Verification Strategy

Threat Level Assessment:
├── PUBLIC (internet agents, unknown skills)
│   ├── Actions: Full mTLS + JWS + capability tokens + WASM sandbox
│   ├── Audit: Every action logged with Merkle proof
│   └── TTL: Max 5min capability lifetime
├── INTERNAL (trusted agent cluster)
│   ├── Actions: mTLS + JWS + capabilities (longer TTL)
│   ├── Audit: Aggregate logging with daily root publish
│   └── TTL: Max 1hr capability lifetime
└── DEV/TEST (localhost, development)
    ├── Actions: Optional mTLS + basic capabilities
    ├── Audit: Local file logs (no Merkle tree)
    └── TTL: Max 24hr capability lifetime

2. Agent Request → Capability Check → Grant/Deny Logic

Incoming Agent Request Processing:
├── 1. Verify mTLS certificate chain
│   ├── Valid CA signature? → Continue
│   └── Invalid/expired? → REJECT immediately
├── 2. Parse JWS message envelope
│   ├── Signature valid + not expired? → Continue
│   ├── Replay detected (jti cache)? → REJECT
│   └── Signature invalid? → REJECT + log security event
├── 3. Check required capabilities
│   ├── Agent holds exact capability? → GRANT
│   ├── Agent holds broader capability? → ATTENUATE + GRANT
│   ├── Capability expired? → REJECT + force refresh
│   └── No matching capability? → REJECT + suggest minimal grant
└── 4. Execute with sandbox constraints
    ├── WASM skills: CPU/memory limits enforced
    ├── File operations: Path validation against capabilities
    └── Network calls: Destination validation against capabilities

3. Delegation Chain → Trust Depth Decision

Capability Delegation Request:
├── Parent capability delegatable=true?
│   ├── Yes → Check remaining depth
│   │   ├── Depth > 0 → Allow with depth-1
│   │   └── Depth = 0 → REJECT (max delegation reached)
│   └── No → REJECT (not delegatable)
├── Requested actions ⊆ parent actions?
│   ├── Yes → Allow subset
│   └── No → REJECT (cannot escalate privileges)
└── Trust boundary crossed?
    ├── Same orchestrator domain → Allow
    └── Different domain → Require explicit cross-domain capability

Failure Modes

1. Ambient Authority Leakage

Detection: grep -r "process.env" agent_code/ shows environment variable access without capability check Symptom: Agent accesses resources it shouldn't have permissions for Fix: Replace with explicit capability tokens scoped to exact resources needed

2. Message Replay Attack

Detection: Multiple audit log entries with identical jti (message ID) or timestamps within replay window Symptom: Agent receives and processes the same command multiple times Fix: Implement jti deduplication cache with TTL matching message expiry

3. Capability Escalation Through Delegation

Detection: Child capability has more actions than parent, or delegation depth exceeded configured maximum Symptom: Sub-agents gain more privileges than their parent delegator intended Fix: Enforce attenuation invariant: child capabilities ⊆ parent capabilities at delegation time

4. Sandbox Escape Through Resource Exhaustion

Detection: Agent CPU usage >95% for >30 seconds, or memory usage approaching sandbox limits Symptom: Agent attempts infinite loops or excessive memory allocation to break out of constraints Fix: Hard-kill agent process at resource limits, implement fuel-based execution metering

5. Trust-on-First-Use (TOFU) Certificate Acceptance

Detection: Agent accepts certificate without CA verification on first connection Symptom: Man-in-the-middle attacks succeed by presenting any certificate Fix: Pre-provision all agent certificates, maintain explicit trust store, reject unknown CAs

Worked Examples

Example 1: Multi-Agent Message Signing Pipeline

Scenario: Research agent needs to pass analysis to code generation agent, then to review agent.

Setup Phase:

// Orchestrator mints capabilities
const researchCap = mint.mint('fs:/tmp/research/**', ['read','write'], 'agent-research-001');
const codegenCap = mint.mint('fs:/workspace/src/**', ['read','write'], 'agent-codegen-001'); 
const reviewCap = mint.mint('fs:/workspace/**', ['read'], 'agent-review-001');

Message Flow:

  1. Research → Codegen: Research agent creates JWS-signed message:

    Header: {alg: 'EdDSA', kid: 'agent-research-001/v1'}
    Payload: {
      iss: 'agent-research-001',
      sub: 'agent-codegen-001', 
      dag_id: 'proj-alpha-v1',
      action: 'task',
      body: {analysis: "API needs OAuth2 flow", output_path: "/tmp/research/api_analysis.json"}
    }
    
  2. Codegen Verification: Codegen agent receives message:

    • Verifies JWS signature against research agent's public key
    • Checks message TTL (not expired)
    • Validates jti not in replay cache
    • Confirms dag_id matches current execution context
    • Expert catch: Verifies research agent had capability for output_path
  3. Codegen → Review: Codegen creates signed result:

    {
      "iss": "agent-codegen-001",
      "sub": "agent-review-001",
      "action": "result", 
      "body": {"generated_files": ["/workspace/src/auth.ts"], "confidence": 0.87}
    }
    

Novice miss: Would skip jti replay protection, allowing duplicate processing. Expert insight: Audit trail shows complete message chain with cryptographic proof of custody.

Example 2: Capability Token Issuance with Attenuation

Scenario: Main agent needs to delegate file analysis to specialized sub-agent, but restrict access to sensitive directories.

Initial Grant:

// Orchestrator grants broad filesystem access
const mainCap = mint.mint('fs:/project/**', ['read','write','execute'], 'agent-main', {
  delegatable: true,
  maxDepth: 2,
  ttlSeconds: 3600
});

Attenuation Decision Tree:

Main agent evaluating delegation request:
├── Sub-agent requests: fs:/project/src/** [read]
│   ├── /project/src/** ⊂ /project/** ? YES
│   ├── [read] ⊂ [read,write,execute] ? YES  
│   ├── Delegation depth 2 > 0 ? YES
│   └── GRANT: Create attenuated capability
├── Sub-agent requests: fs:/project/secrets/** [read]  
│   ├── Path contains "secrets" → Security policy violation
│   └── REJECT: Sensitive path exclusion
└── Sub-agent requests: fs:/etc/passwd [read]
    ├── /etc/passwd ⊂ /project/** ? NO
    └── REJECT: Outside authorized scope

Attenuated Capability Generated:

const subCap = mint.attenuate(mainCap, 'agent-analyzer-001', ['read']);
// Results in: fs:/project/src/** [read] delegatable=true maxDepth=1 ttl=3600s

Novice miss: Would grant full parent capability without restriction. Expert insight: Attenuation enforces "never escalate privileges" at the cryptographic level.

Example 3: Sandbox Policy Violation Detection with Trade-off Analysis

Scenario: Code generation agent attempts to access network during execution, violating sandbox policy.

Sandbox Configuration:

const codegenSandbox = {
  fileRead: ['/workspace/src/**', '/workspace/package.json'],
  fileWrite: ['/workspace/src/**'], 
  netConnect: false,  // NO network access
  maxExecutionMs: 300000,
  maxMemoryMb: 512
};

Violation Detection Flow:

  1. Agent Action: Codegen attempts fetch('https://api.github.com/repos/...')

  2. Sandbox Intercept: WASM runtime catches syscall for network socket

  3. Policy Check: netConnect: false → VIOLATION DETECTED

  4. Trade-off Analysis:

    Security vs Functionality Trade-offs:
    ├── STRICT (current): Block network, terminate agent
    │   ├── Pro: Zero network attack surface
    │   ├── Con: Cannot fetch external dependencies/docs
    │   └── Decision: ENFORCE (security-first environment)
    ├── MODERATE: Allow specific whitelisted domains
    │   ├── Pro: Functional for known-good APIs  
    │   ├── Con: DNS poisoning, subdomain takeover risks
    │   └── Decision: Consider for dev environments only
    └── PERMISSIVE: Log but allow
        ├── Pro: Full functionality preserved
        ├── Con: Agent can exfiltrate data, download malware
        └── Decision: REJECT (violates zero-trust model)
    
  5. Response: Terminate agent, log security event:

    {
      "event": "sandbox_violation",
      "agent_id": "agent-codegen-001", 
      "violation_type": "unauthorized_network_access",
      "attempted_url": "api.github.com",
      "policy_matched": "netConnect: false",
      "action_taken": "terminate_agent"
    }
    

Novice miss: Would allow the network access "just this once" or not detect the violation. Expert insight: Sandbox violations indicate potential compromise or model drift—always enforce strictly.

Quality Gates

  • Every agent has unique cryptographic identity (Ed25519 keypair + certificate)
  • All agent-to-agent channels use mutual TLS with certificate verification
  • All messages carry JWS signatures with <5min TTL and jti replay protection
  • Capability tokens follow ocap model (no ambient authority anywhere)
  • Capability delegation preserves attenuation invariant (child ⊆ parent privileges)
  • Audit trail uses append-only Merkle tree with published roots
  • All skill execution occurs in WASM or container sandbox
  • Resource limits enforced (CPU, memory, execution time, network)
  • Skill packages are content-addressed and author-signed
  • No agent accepts unsigned or unverified skills/inputs
  • Certificate rotation automated with <24hr certificate lifetime
  • Replay detection cache operational with TTL matching message expiry
  • All security violations logged with timestamp + agent identity + action taken

NOT-FOR Boundaries

This skill should NOT be used for:

  • Application-level vulnerability scanning → Use security-auditor instead
  • Network firewall/WAF configuration → Use infrastructure-engineer instead
  • SOC2/HIPAA compliance documentation → Use organizational compliance processes
  • Prompt injection defense → Use prompt-engineer skill instead
  • Rate limiting or DDoS protection → Use API gateway configuration
  • Container orchestration security → Use devops-automator skill instead

Delegation boundaries:

  • For code-level security issues → security-auditor
  • For infrastructure hardening → infrastructure-engineer
  • For secure coding practices → software-engineer
  • For incident response → security-incident-response

Individual skills in this repo

This repo contains 20 individual skills — each has its own dedicated page.

curiositech/windags-skills

Expert in 2000s-era music visualization (Milkdrop, AVS, Geiss) and modern WebGL implementations. Specializes in Butterchurn integration, Web Audio API AnalyserNode FFT data, GLSL shaders for audio-reactive visuals, and psychedelic generative art. Activate on "Milkdrop", "music visualization", "WebGL visualizer", "Butterchurn", "audio reactive", "FFT visualization", "spectrum analyzer". NOT for simple bar charts/waveforms (use basic canvas), video editing, or non-audio visuals.

curiositech/windags-skills

Expert legal research agent for finding and scraping expungement data state by state. Knows authoritative sources, URL patterns, Firecrawl configuration, and 2026 legal landscape.

curiositech/windags-skills

Expert in 3D computer vision labeling tools, workflows, and AI-assisted annotation for LiDAR, point clouds, and sensor fusion. Covers SAM4D/Point-SAM, human-in-the-loop architectures, and vertical-specific training strategies. Activate on '3D labeling', 'point cloud annotation', 'LiDAR labeling', 'SAM 3D', 'SAM4D', 'sensor fusion annotation', '3D bounding box', 'semantic segmentation point cloud'. NOT for 2D image labeling (use clip-aware-embeddings), general ML training (use ml-engineer), video annotation without 3D (use computer-vision-pipeline), or VLM prompt engineering (use prompt-engineer).

curiositech/windags-skills

Implement WCAG 2.2 AA/AAA compliance with automated testing, keyboard navigation, screen reader support, and focus management. Activate on: accessibility audit, WCAG compliance, keyboard navigation, screen reader, aria attributes, axe-core, focus trap. NOT for: design-level accessibility review (use design-accessibility-auditor), color contrast only (use css-in-js-architect).

curiositech/windags-skills

Time-blind friendly planning, executive function support, and daily structure for ADHD brains. Specializes in realistic time estimation, dopamine-aware task design, and building systems that actually work for neurodivergent minds.

curiositech/windags-skills

Designs digital experiences for ADHD brains using neuroscience research and UX principles. Expert in reducing cognitive load, time blindness solutions, dopamine-driven engagement, and compassionate design patterns. Activate on 'ADHD design', 'cognitive load', 'accessibility', 'neurodivergent UX', 'time blindness', 'dopamine-driven', 'executive function'. NOT for general accessibility (WCAG only), neurotypical UX design, or simple UI styling without ADHD context.

curiositech/windags-skills

>- Apply crisis decision-making research to agent routing, uncertainty triage, and coordination failure analysis in time-pressured systems. Use when diagnosing handoff failures, analytical paralysis, or expert judgment under incomplete information. NOT for routine coding, simple CRUD design, or static single-agent tasks with complete information.

curiositech/windags-skills

Extend and modify the admin dashboard, developer portal, and operations console. Use when adding new admin tabs, metrics, monitoring features, or internal tools. Activates for dashboard development, analytics, user management, and internal tooling.

curiositech/windags-skills

Conversation patterns and interaction protocols for multi-agent systems. Covers request/response, pub/sub, blackboard, delegation chains, debate, critique, consensus, fan-out/fan-in, supervisor-worker, and peer negotiation. Deep analysis of AutoGen conversation patterns, CrewAI delegation, LangGraph state passing, and FIPA-ACL performatives. Teaches how to design what agents say to each other and in what order. Activate on: "agent conversation", "agent protocol", "multi-agent debate", "agent delegation", "supervisor worker pattern", "agent voting", "consensus protocol", "fan-out fan-in", "agent negotiation", "blackboard pattern", "agent dialogue", "conversation topology", "agent handoff". NOT for: wire format or serialization (use agent-interchange-formats), orchestration infrastructure (use agentic-infrastructure-2026), single agent behavior (use agentic-patterns).

curiositech/windags-skills

Meta-agent for creating new custom agents, skills, and MCP integrations. Expert in agent design, MCP development, skill architecture, and rapid prototyping. Activate on 'create agent', 'new skill', 'MCP server', 'custom tool', 'agent design'. NOT for using existing agents (invoke them directly), general coding (use language-specific skills), or infrastructure setup (use deployment-engineer).

curiositech/windags-skills

AI-powered calendar management and agent-based scheduling coordination. Covers calendar APIs (Google Calendar, CalDAV/iCal), AI scheduling assistants (Reclaim, Clockwise, Motion, Cal.com), building custom calendar agents with MCP, multi-calendar merging, timezone management, focus block protection, meeting fatigue detection, and agent-to-agent meeting negotiation protocols. Activate on: "calendar agent", "AI scheduling", "calendar coordination", "meeting scheduling", "calendar API", "focus time protection", "calendar optimization", "Google Calendar MCP", "Reclaim", "Clockwise", "Motion", "Cal.com", "smart scheduling", "calendar-aware agent", "timezone scheduling", "agent negotiation meetings". NOT for: manual calendar UI component design (use form-validation-architect), project management scheduling or Gantt charts (use project-management-guru-adhd), general time-tracking or pomodoro apps (use adhd-daily-planner for time-awareness), building the agent itself from scratch (use agent-creator).

curiositech/windags-skills

Build and adopt production AI agent infrastructure in 2026. Covers framework selection (LangGraph, CrewAI, AutoGen, MCP), orchestration patterns, evaluation, observability, memory systems, and tool use. Also covers the SOCIAL dimension: how to sell agent infrastructure internally, change management, measuring ROI, building trust in autonomous systems, and scaling adoption across teams. Activate on: "agent infrastructure", "agent framework comparison", "which agent framework", "sell AI tools internally", "agent adoption", "agent observability", "agent evaluation", "MCP architecture", "agentic mesh", "enterprise AI agents", "AI change management", "agent ROI". NOT for: building specific agents (use ai-engineer), designing agent behavior patterns (use agentic-patterns), prompt tuning (use prompt-engineer).

curiositech/windags-skills

Fundamental patterns for effective agentic behavior. Teaches decomposition, tool orchestration, error recovery, context management, quality self-assessment, and knowing when to stop. Model-agnostic principles that make any agent more effective regardless of domain. Activate on: "how should I structure this agent", "agentic workflow", "agent patterns", "multi-step task", "tool orchestration", "/agentic-patterns", "decompose this", "agent best practices", "chain of actions", "when should the agent stop", "agent loop design". NOT for: creating agent infrastructure (use agent-creator), building DAGs (use windags-architect), specific tool implementation.

curiositech/windags-skills

Automated discovery and matching of agent skills for dynamic task routing and capability assessment

curiositech/windags-skills

Data structures and serialization formats for agent-to-agent communication. Covers message envelopes, structured output schemas, capability declarations, task handoff payloads, error/retry signaling, and context windows as data structures. Deep comparison of A2A protocol, MCP, OpenAI function calling, and LangChain message types. Teaches when to use rigid schemas vs free-form with validation, typed vs untyped, streaming vs batch. Activate on: "agent message format", "agent communication schema", "agent-to-agent protocol", "A2A protocol", "MCP message format", "structured output for agents", "agent interop", "interchange format", "agent serialization", "task handoff format", "capability declaration". NOT for: what agents say to each other (use agent-conversation-protocols), orchestration topology (use multi-agent-coordination), building agent infrastructure (use agentic-infrastructure-2026).

curiositech/windags-skills

Logic-based agent programming language implementing BDI architecture for practical autonomous agent development

curiositech/windags-skills

>- Design AgentSpeak(L)-style BDI agents with context-guarded plans, selection functions, and intention stacks. Use for interruptible autonomy, agent policy, and multi-agent orchestration in dynamic environments. NOT for simple rule engines, static planners, or centralized workflows.

curiositech/windags-skills

Foundational concurrent computation model where actors communicate exclusively through asynchronous message passing

curiositech/windags-skills

Build production-ready LLM applications, advanced RAG systems, and intelligent agents. Implements vector search, multimodal AI, agent orchestration, and enterprise AI integrations. Use PROACTIVELY for LLM features, chatbots, AI agents, or AI-powered applications.

curiositech/windags-skills

license: Apache-2.0 NOT for unrelated tasks outside this domain.

Habilidades Relacionadas