Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Generate a local repository risk receipt before Claude Code or other AI-agent edits. Use when the user asks to prepare a repository for agent changes, check for risky hooks or credential-writing automation, or run the /agent-preflight command. Trigger with "run agent preflight", "check this repo before agent edits", or "/agent-preflight".
.claude/skills/jeremylongshore-agent-safety-preflight/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-02 | ✗→✓ | ▲ Improved | 176% | 0% |
| case-04 | ✗→✓ | ▲ Improved | -8% | 0% |
| case-06 | ✗→✓ | ▲ Improved | 10% | 0% |
| case-07 | ✗→✓ | ▲ Improved | 19% | 0% |
| case-08 | ✗→✓ | ▲ Improved | 65% | 0% |
Agent Safety Preflight helps Claude inspect a local repository before making AI-agent-assisted edits. It produces a compact Green, Yellow, or Red risk receipt from local files only, with special attention to destructive shell patterns, credential-writing automation, agent authority surfaces, uncommitted changes, and unavailable git state.
The skill pairs with the /agent-preflight command in this plugin. Prefer the bundled lightweight scanner when it is available from a trusted Claude install root, then explain the decision and next safe action before editing.
agent_preflight_lite.py scanner.Do not send source, secrets, tokens, private repository contents, payment credentials, or environment variables to external services while using this skill.
Read only for local documentation or configuration files that explain the workspace; do not copy private source into the response./agent-preflight when the command is installed, or invoke the bundled scanner from a trusted Claude install root.Return a short receipt in Markdown that is safe to paste into the local work log or pull request notes:
markdown## Agent Safety Preflight Receipt - Decision: Green | Yellow | Red - Repository: <path> - Git state: clean | dirty | unavailable - Risk buckets: <bullets> - Evidence: <file/path markers> - Next safe action: proceed | checkpoint | stop
.claude/, .cursor/, .github/, shell scripts, JSON/YAML/TOML config, package manifests, and environment files.User request: "Run a preflight before you update this README."
The skill runs the scanner, sees a clean git state and no high-risk automation markers, then returns Green with the repository path and evidence summary.
User request: "Check this repo before the agent refactor."
The skill detects agent hook configuration or broad tool permissions, returns Yellow, and recommends a checkpoint or narrower edit scope before continuing.
User request: "Start editing this generated-project repo."
The skill finds a destructive recursive delete pattern in an automation file, returns Red, and stops until a human reviews the workflow.
plugins/security/agent-safety-preflight/commands/agent-preflight.mdplugins/security/agent-safety-preflight/scripts/agent_preflight_lite.pyreferences/decision-rules.md| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | fail→fail | 3,626 | 5,585 | +54% | 1 | 1 | 0% | 179 | 1,368 | +664% | 0 | 0 | — |
case-02 | fail→pass | 6,610 | 10,520 | +59% | 1 | 1 | 0% | 833 | 2,296 | +176% | 0 | 0 | — |
case-03 | fail→fail | 16,019 | 16,817 | +5% | 1 | 1 | 0% | 512 | 1,234 | +141% | 0 | 0 | — |
case-04 | fail→pass | 15,969 | 9,592 | -40% | 1 | 1 | 0% | 1,804 | 1,667 | -8% | 0 | 0 | — |
case-05 | pass→pass | 9,220 | 3,571 | -61% | 1 | 1 | 0% | 1,636 | 1,636 | 0% | 0 | 0 | — |
case-06 | fail→pass | 17,260 | 13,508 | -22% | 1 | 1 | 0% | 1,632 | 1,803 | +10% | 0 | 0 | — |
case-07 | fail→pass | 10,621 | 4,301 | -60% | 1 | 1 | 0% | 1,399 | 1,667 | +19% | 0 | 0 | — |
case-08 | fail→pass | 9,708 | 7,012 | -28% | 1 | 1 | 0% | 870 | 1,436 | +65% | 0 | 0 | — |
case-09 | fail→pass | 5,798 | 4,044 | -30% | 1 | 1 | 0% | 1,047 | 1,660 | +59% | 0 | 0 | — |
case-10 | pass→pass | 10,761 | 8,670 | -19% | 1 | 1 | 0% | 1,888 | 2,695 | +43% | 0 | 0 | — |
case-11 | fail→pass | 4,195 | 5,208 | +24% | 1 | 1 | 0% | 807 | 1,765 | +119% | 0 | 0 | — |
case-12 | pass→pass | 9,937 | 9,642 | -3% | 1 | 1 | 0% | 1,083 | 1,959 | +81% | 0 | 0 | — |
case-13 | fail→pass | 6,093 | 4,846 | -20% | 1 | 1 | 0% | 1,120 | 1,855 | +66% | 0 | 0 | — |
case-14 | fail→pass | 9,648 | 5,361 | -44% | 1 | 1 | 0% | 1,883 | 1,899 | +1% | 0 | 0 | — |
case-15 | fail→pass | 4,362 | 3,478 | -20% | 1 | 1 | 0% | 152 | 1,456 | +858% | 0 | 0 | — |
case-16 | fail→pass | 5,985 | 4,070 | -32% | 1 | 1 | 0% | 964 | 1,627 | +69% | 0 | 0 | — |
case-17 | pass→pass | 6,149 | 6,017 | -2% | 1 | 1 | 0% | 1,059 | 1,979 | +87% | 0 | 0 | — |
case-18 | fail→pass | 6,165 | 3,989 | -35% | 1 | 1 | 0% | 1,089 | 1,485 | +36% | 0 | 0 | — |
case-19 | pass→pass | 14,612 | 6,650 | -54% | 1 | 1 | 0% | 2,721 | 2,163 | -21% | 0 | 0 | — |
case-20 | fail→fail | 5,819 | 6,186 | +6% | 1 | 1 | 0% | 755 | 1,683 | +123% | 0 | 0 | — |
case-21 | fail→fail | 13,722 | 13,860 | +1% | 1 | 1 | 0% | 859 | 1,833 | +113% | 0 | 0 | — |
case-22 | fail→fail | 4,421 | 2,645 | -40% | 1 | 1 | 0% | 765 | 1,237 | +62% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted, and 19 counted toward the lift figure. The other 3 produced results that are not comparable between the two arms, so they are excluded from the headline rather than averaged into it. The headline lift of +55 percentage points is the difference between those two pass rates over the 19 comparable cases.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.