A playbook is the case for a check, written out: what the defect is, why
reading the configuration cannot settle it, the probe flow ending at a
verdict, the fixture that has the defect and the one that does not, and the
proof that the check separates them. The templates repository keeps one
beside each of its differentiated checks and these pages are the canonical
copy of them.
They are the best answer to “how do I know this check is worth running”,
and the best model to follow when
contributing one.
| Playbook |
Checks it covers |
| Agent extension installer path containment (“SkillSlip”) |
agent-extension-install-path-containment |
| Agent-plugin loader containment & load-time side effects |
agent-plugin-loader-conformance |
| Agent skill hidden-instruction trust failure |
agent-skill-hidden-instruction-trust |
| Agent command-trace composition bypass |
coding-agent-command-trace-composition |
| Cross-agent config & marketplace bleed |
coding-agent-cross-tool-config-bleed |
| The deny rule you can walk around (one file, one rule, eleven ways in, and a symlink swapped mid-check) |
coding-agent-deny-rule-reachability |
| Execution authority: what a coding-agent CLI will run on someone else’s say-so |
coding-agent-shared-config-trust, coding-agent-project-local-config-trust, coding-agent-config-allowlist-trust |
GitSpawn: untrusted .git/config executes code through the agent’s background git |
coding-agent-git-config-exec |
| The hook that does not hold (a security control you installed, and nobody ever tested) |
coding-agent-hook-gate-integrity |
| Repo-supplied agent config auto-execution |
coding-agent-repo-config-autoexec |
| Repo-config credential / endpoint redirect |
coding-agent-repo-config-credential-redirect |
| The decorative sandbox (a confinement control that removed your approval prompt and confines nothing) |
coding-agent-sandbox-perimeter-enforcement |
| Agent sandbox trust-handoff escape (deferred execution of agent-written files) |
coding-agent-sandbox-trust-handoff |
| Interpreter search-path shadowing in an untrusted workspace |
coding-agent-workspace-interpreter-shadowing |
MCP CacheableResult cross-identity leak (cacheScope: "public" on an identity-dependent response) |
mcp-cache-scope-identity-leak |
| MCP child-process credential blast radius |
mcp-child-env-inheritance |
The model writes a header line: x-mcp-header value encoding on the client |
mcp-client-header-value-encoding, mcp-client-oauth-issuer-binding |
MCP client MRTR conformance (inputRequests provenance & the resultType default) |
mcp-client-mrtr-conformance |
| MCP client OAuth issuer binding (authorization-server mix-up & cross-issuer credential reuse) |
mcp-client-oauth-issuer-binding |
A boolean turns off the human: readOnlyHint auto-approval on the client |
mcp-client-untrusted-annotation-approval, mcp-client-header-value-encoding, mcp-client-mrtr-conformance |
| MCP out-of-scope tool action |
mcp-excessive-scope-proof |
MCP handle binding and requestState integrity |
mcp-handle-binding-integrity |
| The listing is not the server: diffing what an MCP server declared against what it serves |
mcp-manifest-runtime-divergence |
| Routing-header desync: when the gateway and the server read different requests |
mcp-method-desync |
| MCP OAuth consent-layer confused deputy via open DCR |
mcp-oauth-consent-dcr-abuse |
| Precise MCP metadata scanning |
mcp-tool-poisoning, mcp-credential-exposure, mcp-invisible-unicode-poisoning, mcp-broken-token-validation |
| Install-time credential access and workflow planting |
supply-chain-install-credential-access, supply-chain-install-hook-behavior |