Open-Source Agent Skill 'Foreman' Helps Coding Agents Design & Review Tools Safely
blair_hudson · reddit · 2026-07-05
The author open-sourced Foreman, an agent skill that helps coding agents like Claude Code and Codex identify often-overlooked security issues when designing or reviewing tools (including MCP and native framework tool calls). It checks for capability boundaries, authorization, side effects, idempotency, confused deputy risks, and failure modes. The author previously authored a book on generative AI tool security and topped Amazon Australia's bestseller list.
Foreman is currently operational. The author states the next step is to figure out how to evaluate this skill (exploring eval methods for agent skills) and is soliciting feedback and ideas from the community in their post.
Related event: Open-Sourcing Foreman to Help Coding Agents Safely Review Tools(2 posts)→
More from coding & agent
- GPT-6 Astra beats Factorio with enemies in 44 in-game hours at ~$4,500 API cost — liminal_bardo · 2026-09-11
- Investment Analyst Asks How to Build a Claude-Based Diligence Agent Stack — Careless_Tie2286 · 2026-09-11
- Treating agents like 50 First Dates: a 3-layer context system so every conversation doesn't start from zero — evielync · 2026-09-11
- Running the Firefox MCP on Android via Termux, ngrok, and mcp-proxy — Nervous-Strain7544 · 2026-09-11
- SmolVM open-sources persistent computer infrastructure for agents that outlive chat sessions — aniketmaurya · 2026-09-11
- ARRM targets silent economic regressions in AI agents that functional tests miss — Beautiful_Belt_601 · 2026-09-11