Atlas / Skills / ganyuanran / Aegis

AegisCAUTION

skills/ganyuanran/aegis

Make AI coding agents architecture-aware: baseline-first, evidence-verified, drift-checked, and safe across long tasks.

Verdict
CAUTION
Grade
C
Trust score
76 /100
Version
—
Hosts
7 documented
License
MIT
Stars
1,329
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

<img src="https://img.shields.io/badge/LINUX-DO-FFB003.svg?logo=data:image/svg%2bxml;base64,DQo8c3ZnIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAiIHdpZHRoPSIxMDAiIGhlaWdodD0iMTAwIj48cGF0aCBkPSJNNjguMi0uMDU1aDYuMjVxMjMuOTY5IDIuMDYyIDM4IDIxLjQyNmM1LjI1OCA3LjY3NiA4LjIxNSAxNi4xNTYgOC44NzUgMjUuNDV2Ni4yNXEtMi4wNjQtMjMuOTY4LTIxLjQzIDM4LTExLjUxMiA3Ljg4NS0yNS40NDUgOC44NzRoLTYuMjVxLTIzLjk3LTIuMDY0LTM4LjAwNC0yMS40M1EuOTcxIDY3LjA1Ni0uMDU0IDUzLjE4di02LjQ3M0MxLjM2MiAzMC43ODEgOC41MDMgMTguMTQ4IDIxLjM3IDguODE3IDI5LjA0NyAzLjU2MiAzNy41MjcuNjA0IDQ2LjgyMS0uMDU2IiBzdHlsZT0ic3Ryb2tlOm5vbmU7ZmlsbC1ydWxlOmV2ZW5vZGQ7ZmlsbDojZWNlY2VjO2ZpbGwtb3BhY2l0eToxIi8+PHBhdGggZD0iTTQ3LjI2NiAyLjk1N3EyMi41My0uNjUgMzcuNzc3IDE1LjczOGE0OS43IDQ5LjcgMCAwIDEgNi44NjcgMTAuMTU3cS00MS45NjQuMjIyLTgzLjkzIDAgOS43NS0xOC42MTYgMzAuMDI0LTI0LjM4N2E2MSA2MSAwIDAgMSA5LjI2Mi0xLjUwOCIgc3R5bGU9InN0cm9rZTpub25lO2ZpbGwtcnVsZTpldmVub2RkO2ZpbGw6IzE5MTkxOTtmaWxsLW9wYWNpdHk6MSIvPjxwYXRoIGQ9Ik03Ljk4IDcwLjkyNmMyNy45NzctLjAzNSA1NS45NTQgMCA4My45My4xMTNRODMuNDI2IDg3LjQ3MyA2Ni4xMyA5NC4wODZxLTE4LjgxIDYuNTQ0LTM2LjgzMi0xLjg5OC0xNC4yMDMtNy4wOS0yMS4zMTctMjEuMjYyIiBzdHlsZT0ic3Ryb2tlOm5vbmU7ZmlsbC1ydWxlOmV2ZW5vZGQ7ZmlsbDojZjlhZjAwO2ZpbGwtb3BhY2l0eToxIi8+PC9zdmc+" />

Read from source at commit 02d6bfc10258OBSERVED · 2026-10-09
02

Install

Commands as the repository documents them. They are shown, not run.

git clone https://github.com/GanyuanRan/Aegis.git ~/.codex/aegis
git clone https://github.com/GanyuanRan/Aegis.git "$AEGIS_DIR"
git clone https://github.com/GanyuanRan/Aegis.git $AegisDir
git clone https://github.com/GanyuanRan/Aegis.git "$AEGIS_DIR"
git clone https://github.com/GanyuanRan/Aegis.git $AegisDir
npm installation instructions. No official npm registry channel is being
03

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
claude-codementioned
codexmentioned
copilotmentioned
cursormentioned
gemini-climentioned
openclawmentioned
windsurfmentioned
04

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: anti-entropy-governance
description: "Use when touching retiring old logic, collapsing duplicate owners, removing fallbacks, or schema/persistence/source-of-truth boundaries; identify opportunities automatically; destructive execution requires explicit confirmation."
---

# Anti-Entropy

## Overview

Use this skill when the task is not merely "change code" but "remove old paths
safely without growing entropy".

This skill chooses between:

- `delete-first` for internal code retirement
- `compat-exception` for proven external dependency boundaries
- `confirmation-first` for irreversible state or an external contract whose
  distributed consumers cannot be observed

It does not replace `brainstorming`, `writing-plans`,
`systematic-debugging`, or `verification-before-completion`. It is a narrow
governance owner for retirement, fallback collapse, duplicate-owner cleanup,
and deletion safety.

## When to Use

Use when any of these are true:

- old logic, duplicate owners, or stale fallbacks should be retired
- a candidate fix is "delete old path" vs "add another fallback"
- internal keyword / phrase / trigger logic is being replaced by structured logic
- a new canonical owner exists and the old owner may still carry real behavior
- a cleanup, migration, or deprecation task touches schema, persistence,
  source-of-truth, or external compatibility boundaries
- the task risks confusing code retirement with live data deletion

Do not use for:

- pure additive feature work with no retirement decision
- tiny wording edits
- simple status or read-only Q&A
- normal bug fixes that do not involve owner collapse, fallback cleanup, or
  deletion choice

## Auto-Compose Boundary

This skill should be composed by other owners. It should not become a new
global hot-path entry.

Prefer composition from:

- `brainstorming` for approach selection involving retirement or persistence risk
- `writing-plans` for plans that delete old paths or touch schema / migration /
  persistence
- `systematic-debugging` when the tempting fix is fallback growth or
  delete-vs-retain
- `verification-before-completion` for cleanup / retirement / compatibility /
  migration closeout

Load automatically when the task touches owner collapse, fallback removal, or schema/persistence/source-of-truth boundaries. Automatic loading identifies and advises only; destructive execution still requires explicit scoped user confirmation.

## Core Principle

Default to reducing internal entropy, not preserving internal history.

Retirement is responsibility-scoped before it is carrier-scoped. Name the
obsolete or duplicated authority first. If the same carrier has a separately
evidenced legitimate role, remove the invalid responsibility and keep only
that role-scoped capability; this is not a compatibility exception. Apply
`delete-first` to the carrier once no legitimate responsibility remains.
Unknown consumers alone still do not justify retaining an internal carrier.

Use this rule:

- internal code retirement -> `delete-first`
- external compatibility boundary -> `compat-exception` with active dependency
  evidence; `confirmation-first` when distribution is proven but consumers
  cannot be observed
- persistent-state or irreversible source-of-truth object ->
  `confirmation-first`

Unknown alone neither proves an external dependency nor blocks internal
`delete-first`. Once distribution is proven, unobservable consumers also do not
prove deletion safe: inspect read-only. Before editing, require user-authored,
scoped authorization that explicitly accepts the concrete external risk.
An informed instruction may already supply it; otherwise disclose the risk
and request scoped confirmation.

Mentioning, loading, or discussing destructive-action rules never authorizes
destructive execution. Without explicit scoped user confirmation:

- no irreversible deletion is executed
- no destructive tool call is made
- no runnable destructive command is emitted as the next action
- no broad assent is reinterpreted as deletion approval

## Deletion Classes

Classify the deletion target first:

- `code-retirement`
  - source code
  - internal triggers
  - duplicate owners
  - stale fallback branches
  - compat-only carriers
  - dead tests/config tied to removed internal behavior

- `contract-carrying code`
  - schema definition files
  - migration files
  - public API contract code
  - host install/discovery code
  - persistence read/write logic

- `live-state mutation surface`
  - code or commands that would mutate live databases, object stores, queues,
    or other persistent state

- `derived-state`
  - rebuildable caches
  - generated indexes
  - temporary exports
  - recomputable artifacts

- `persistent-state`
  - live database tables / columns / rows
  - source-of-truth object storage files
  - user records
  - permission / identity / membership records
  - audit / billing / irreversible business records
  - non-rebuildable queue or event contents

## Default Path By Class

- `code-retirement` -> `delete-first`
- `contract-carrying code` -> classify by the Core Principle; internal-only
  retirement uses `delete-first` with high-risk verification
- `live-state mutation surface` -> inspect and classify; destructive execution
  still requires confirmation when it reaches persistent-state
- `derived-state` -> verify rebuildability first, then decide
- `persistent-state` -> `confirmation-first`

## Hard Stops

If the target is `persistent-state` or another irreversible source-of-truth
object:

- do not execute deletion automatically
- do not emit a runnable destructive command as the next action
- do not call a destructive tool
- do not interpret generic agreement as confirmation
- ask for explicit scoped user confirmation
- request backup / rollback / migration note when relevant

Examples that require confirmation:

- `DROP TABLE`
- `DROP COLUMN`
- `TRUNCATE`
- bulk delete of real business data
- deleting source-of-truth uploaded files
- deleting p
05

Trust audit

CAUTIONgrade C · trust 76/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
found

Findings (18)

MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/helpers/test_agentic_benchmark_process_supervisor.py:627
secret = "private-refresh-token-value"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/helpers/test_run_agentic_benchmark.py:362
secret = "private-refresh-token-value"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/helpers/test_run_agentic_benchmark.py:538
secret = "private-refresh-token-value"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/helpers/test_run_agentic_benchmark.py:856
secret = "private-refresh-token-value"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/helpers/test_run_agentic_benchmark.py:1100
secret = "private-refresh-token-value"
LOWInventory / provenance · inv.hidden_file · CWE-1104
.version-bump.json
.version-bump.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
extensions/dsh/index.js:16
const skillsRoot = fileURLToPath(new URL("../../skills/", import.meta.url));
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/deepseek-harness/test-bootstrap.mjs:14
} from "../../extensions/dsh/bootstrap.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/deepseek-harness/test-bootstrap.mjs:16
const repoRoot = fileURLToPath(new URL("../../", import.meta.url));
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/deepseek-harness/test-peer-compatibility.mjs:13
const manifest = JSON.parse(readFileSync(new URL('../../package.json', import.meta.url), 'utf8'));
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/e2e/agentic-benchmark-cases/tiny-source-boundary/project/test_archive.py:6
assert is_safe_archive_name("exports/../../secrets.zip") is False
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/helpers/test_agentic_benchmark_preflight.py:131
"HTTPS_PROXY": "https://127.0.0.1:443",
LOWNetwork egress · net.tls_off · CWE-200, CWE-319
tests/helpers/test_aegis_update.py:187
entry = self._run_registry_update(tmp, verify=False, verified=False)
Why it matters. certificate verification is disabled
Fix. leave verification on
LOWNetwork egress · net.tls_off · CWE-200, CWE-319
tests/helpers/test_aegis_update.py:195
tmp, verify=False, verified=False, existing=dict(previous)
Why it matters. certificate verification is disabled
Fix. leave verification on
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
README.md:4
src="https://img.shields.io/badge/LINUX-DO-FFB003.svg?logo=data:image/svg%2bxml;base64,DQo8c3ZnIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAiIHdpZHRoPSIxMDAiIGhlaWdodD0iMTAwIj48cGF0aCBkPSJNNjguMi0uMDU1aDYuM
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
README.zh-CN.md:4
src="https://img.shields.io/badge/LINUX-DO-FFB003.svg?logo=data:image/svg%2bxml;base64,DQo8c3ZnIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAiIHdpZHRoPSIxMDAiIGhlaWdodD0iMTAwIj48cGF0aCBkPSJNNjguMi0uMDU1aDYuM
INFOInventory / provenance · inv.oversize · CWE-1104
assets/aegis-hero.png
assets/aegis-hero.png
Why it matters. 1944238 bytes not read
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/README.omp.md:38
install script (`curl -fsSL https://omp.sh/install | sh` on macOS/Linux,

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha 02d6bfc10258full audit observations/trust-audit/skill/ganyuanran__aegis.json · Report an issue / request a re-scan
06

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-0902d6bfc10258CAUTIONC76first audit
07

Questions

What does the Aegis skill do?

Make AI coding agents architecture-aware: baseline-first, evidence-verified, drift-checked, and safe across long tasks.

Is Aegis safe to install?

With care. The audit graded it C (76/100) and found 18 things worth knowing before you trust this skill, listed below with the exact line each was found on.

What can Aegis access on my machine?

The audit observed that it reads or writes files. Each of those is consistent with what it says it does. Secrets in the source: found — see the findings.

Which assistants does Aegis work with?

Its documentation mentions claude-code, codex, copilot, cursor, gemini-cli, openclaw and windsurf. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (02d6bfc10258), read on 2026-10-09. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement