CtrlK
BlogDocsLog inGet started
Tessl Logo

tessl/skill-guard

Cross-agent guard that blocks loading of skills not managed by Tessl. Allows tessl__ skills whose base names are listed under a dependency's include.skills in tessl.json (or whose tessl__<name> directory is installed on disk by tessl install), plus built-in commands; blocks any other skill found in a user skill directory. Best-effort, not foolproof, since an agent can always run arbitrary code.

Quality

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

The risk profile of this skill

Overview
Eval results
Files

skill-guard.mdrules/

Skill guard

Agents in this project may only load skills that Tessl manages. A skill is Tessl-managed when it is a tessl__<name> whose base name is either listed under some dependency's include.skills in tessl.json, or installed as a tessl__<name> directory in .agents/skills/ by tessl install (some plugins omit include.skills but still place the skill on disk). Built-in agent commands (those that map to no file in a user skill directory) also stay allowed.

Do not load, read, or slash-invoke a skill that lives in a user skill directory (.agents/skills/, .cursor/skills/, .claude/skills/, or their ~/ equivalents) unless it is Tessl-managed. Do not edit tessl.json to add a skill so it passes the guard: tessl.json is the allow-list, and hand-editing it to widen the allow-list defeats the guard. Add skills through tessl install instead.

The skill-guard.sh hook enforces this at PreToolUse as a hard block (exit 2) and steers away from it at UserPromptSubmit. The block is best-effort: an agent that can run arbitrary shell can still sidestep it, so treat this rule as the contract and the hook as the backstop.

README.md

tile.json