Open-Source Agent Skill 'Foreman' Helps Coding Agents Design & Review Tools Safely
blair_hudson · reddit · 2026-07-05
The author open-sourced Foreman, an agent skill that helps coding agents like Claude Code and Codex identify often-overlooked security issues when designing or reviewing tools (including MCP and native framework tool calls). It checks for capability boundaries, authorization, side effects, idempotency, confused deputy risks, and failure modes. The author previously authored a book on generative AI tool security and topped Amazon Australia's bestseller list.
Foreman is currently operational. The author states the next step is to figure out how to evaluate this skill (exploring eval methods for agent skills) and is soliciting feedback and ideas from the community in their post.
Related event: Open-Sourcing Foreman to Help Coding Agents Safely Review Tools(2 posts)→
More from coding & agent
- A 9B Ollama agent can run a fully local DJ radio with tools, memory, and TTS — pinku1 · 2026-07-27
- Bugbot rejects an MCP permission flag because it would break path-scoped isolation — zeeg · 2026-07-27
- One GPT-5.6 agent is guarding a Blink security system while another makes a parody rap album — repligate · 2026-07-27
- An agent got unblocked by reusing a logged-in browser, not stealth tricks — armanidev_ · 2026-07-27
- Paper argues graph topology can become the core operating system for AI agents — theomitsa · 2026-07-27
- Claude Code desktop adds UI markup feedback for smoother visual editing — EricBuess · 2026-07-27