Skip to content

Playbooks

A playbook is the case for a check, written out: what the defect is, why reading the configuration cannot settle it, the probe flow ending at a verdict, the fixture that has the defect and the one that does not, and the proof that the check separates them. The templates repository keeps one beside each of its differentiated checks and these pages are the canonical copy of them.

They are the best answer to “how do I know this check is worth running”, and the best model to follow when contributing one.

Playbook Checks it covers
Agent extension installer path containment (“SkillSlip”) agent-extension-install-path-containment
Agent-plugin loader containment & load-time side effects agent-plugin-loader-conformance
Agent skill hidden-instruction trust failure agent-skill-hidden-instruction-trust
Agent command-trace composition bypass coding-agent-command-trace-composition
Cross-agent config & marketplace bleed coding-agent-cross-tool-config-bleed
The deny rule you can walk around (one file, one rule, eleven ways in, and a symlink swapped mid-check) coding-agent-deny-rule-reachability
Execution authority: what a coding-agent CLI will run on someone else’s say-so coding-agent-shared-config-trust, coding-agent-project-local-config-trust, coding-agent-config-allowlist-trust
GitSpawn: untrusted .git/config executes code through the agent’s background git coding-agent-git-config-exec
The hook that does not hold (a security control you installed, and nobody ever tested) coding-agent-hook-gate-integrity
Repo-supplied agent config auto-execution coding-agent-repo-config-autoexec
Repo-config credential / endpoint redirect coding-agent-repo-config-credential-redirect
The decorative sandbox (a confinement control that removed your approval prompt and confines nothing) coding-agent-sandbox-perimeter-enforcement
Agent sandbox trust-handoff escape (deferred execution of agent-written files) coding-agent-sandbox-trust-handoff
Interpreter search-path shadowing in an untrusted workspace coding-agent-workspace-interpreter-shadowing
MCP CacheableResult cross-identity leak (cacheScope: "public" on an identity-dependent response) mcp-cache-scope-identity-leak
MCP child-process credential blast radius mcp-child-env-inheritance
The model writes a header line: x-mcp-header value encoding on the client mcp-client-header-value-encoding, mcp-client-oauth-issuer-binding
MCP client MRTR conformance (inputRequests provenance & the resultType default) mcp-client-mrtr-conformance
MCP client OAuth issuer binding (authorization-server mix-up & cross-issuer credential reuse) mcp-client-oauth-issuer-binding
A boolean turns off the human: readOnlyHint auto-approval on the client mcp-client-untrusted-annotation-approval, mcp-client-header-value-encoding, mcp-client-mrtr-conformance
MCP out-of-scope tool action mcp-excessive-scope-proof
MCP handle binding and requestState integrity mcp-handle-binding-integrity
The listing is not the server: diffing what an MCP server declared against what it serves mcp-manifest-runtime-divergence
Routing-header desync: when the gateway and the server read different requests mcp-method-desync
MCP OAuth consent-layer confused deputy via open DCR mcp-oauth-consent-dcr-abuse
Precise MCP metadata scanning mcp-tool-poisoning, mcp-credential-exposure, mcp-invisible-unicode-poisoning, mcp-broken-token-validation
Install-time credential access and workflow planting supply-chain-install-credential-access, supply-chain-install-hook-behavior