Open-Source Agent Skill 'Foreman' Helps Coding Agents Design & Review Tools Safely
blair_hudson · reddit · 2026-07-05
The author open-sourced Foreman, an agent skill that helps coding agents like Claude Code and Codex identify often-overlooked security issues when designing or reviewing tools (including MCP and native framework tool calls). It checks for capability boundaries, authorization, side effects, idempotency, confused deputy risks, and failure modes. The author previously authored a book on generative AI tool security and topped Amazon Australia's bestseller list.
Foreman is currently operational. The author states the next step is to figure out how to evaluate this skill (exploring eval methods for agent skills) and is soliciting feedback and ideas from the community in their post.
Related event: Open-Sourcing Foreman to Help Coding Agents Safely Review Tools(2 posts)→
More from coding & agent
- Chaining dependent MCP tool calls: no rollback, duplicate risk — agentrsdg · 2026-09-11
- DeepMind-led paper makes design docs the source of truth, code disposable — SMART regenerates in 1.5-3h for ~$100 — Roger_M_Taylor · 2026-09-11
- Agent-built classifier labels 192k docs for $0.70 vs $13-26 with frontier LLMs — vanstriendaniel · 2026-09-11
- MathModelAgent gains traction: auto-solves math modeling and writes a submission-ready paper — jihe520 · 2026-09-11
- alphaXiv open-sources OpenResearch to run parallel research agents with any model — alphaXiv · 2026-09-11
- DeskcommCRM: open-source AI sales CRM with native agents and WhatsApp hits 1k stars — melgarafael · 2026-09-11