Tool Design Security

Use when deciding how an agent tool handles identity, credentials, permissions, scope, and state: injecting secrets server-side instead of through the model, permission gates enforced in code, declared OAuth scopes, audit trails, a who-am-i identity anchor, session context, automatic context injection, and context boundaries such as tenant scope or root paths. Trigger phrases: "API key as a tool parameter", "the agent leaked a secret", "prompt says the agent can't delete", "tenant isolation for tools", "who_am_i tool", "audit log for tool calls", "OAuth scopes per tool".

hashgraph-online Updated

File contents

hashgraph-online/awesome-codex-plugins/tree/main/plugins/runtypelabs/skills/skills/tool-design-security commit a17c446d6d

Frequently asked questions

npx skillmds@latest add hashgraph-online-awesome-codex-plugins/tool-design-security