miii-security
v1.0.3
Published
Security-focused `SKILL.md` packs for reviewing and hardening LLM systems.
Downloads
432
Maintainers
Readme
mii-ai-security
Security-focused SKILL.md packs for reviewing and hardening LLM systems.
Each skill is a self-contained review guide: a first principle, an attack mental model, a control lens table, named controls with Check/Action/Failure Mode sections, and a Quick Win. Fetch one, apply it to a codebase or design, ship the finding.
Quick Start
Install via npm: miii-security · Source: maruakshay/mii-ai-security
# Add a skill to your project (copies to .claude/skills/<name>/SKILL.md)
npx miii-security add rag-security
# List all available skills
npx miii-security list
# Print a skill to stdout
npx miii-security show fine-tuning-securityWhat's In Scope
58 skills across twelve buckets:
| Bucket | Count | Coverage | |---|---|---| | Base | 4 | Prompts, RAG, tools, system infrastructure | | Companion | 9 | Memory, governance, leakage, agentic trust, multimodal, model supply chain, indirect injection, fine-tuning, embedding attacks | | Framework | 14 | LangChain, LlamaIndex, Haystack, DSPy, Semantic Kernel, OpenAI APIs, AutoGen, CrewAI, llamafile, Ollama, LiteLLM, Guardrails AI, NeMo Guardrails | | Attack surface | 5 | Red-teaming, jailbreak taxonomy, adversarial robustness, model inversion, federated learning | | Runtime/deployment | 3 | Model watermarking, inference API abuse, KV cache security | | Agentic/multi-agent | 3 | Memory poisoning, tool schema injection, HITL bypass | | Data pipeline | 3 | Training data poisoning, dataset supply chain, synthetic data | | Identity/authz | 2 | Agent identity, multi-tenant isolation | | Evasion/detection | 3 | Content authenticity, output fingerprinting, AI social engineering | | Emerging | 3 | LLM DoS, multi-agent coordination attacks, browser agent security | | Infra/ops | 5 | MLOps pipelines, GPU infrastructure, model serving, containers, secrets detection | | Compliance/governance | 4 | Audit logging, red team programs, third-party model risk, AI privacy/PII | | Test & reference | — | Adversarial fixtures, severity guidance, OWASP/MITRE mappings |
Skill List
Base
core-llm-prompt-securityrag-securitytool-use-execution-securitysystem-infrastructure-security
Companion
data-leakage-preventionagentic-trust-boundariesmemory-securitymodel-supply-chain-securityindirect-prompt-injectionmultimodal-securityai-governance-and-incident-responsefine-tuning-securityembedding-attack-security
Framework subskills
langchain-rag-securityllamaindex-rag-securityhaystack-rag-securitydspy-program-securitysemantic-kernel-tool-securityopenai-responses-tool-file-securityopenai-assistants-legacy-securityautogen-multiagent-securitycrewai-agent-securityllamafile-local-model-securityollama-securitylitellm-proxy-securityguardrails-ai-securitynemo-guardrails-security
Attack surface
prompt-injection-red-teamingjailbreak-taxonomyadversarial-robustnessmodel-inversion-membership-inferencefederated-learning-security
Infra/ops
mlops-pipeline-securitygpu-infrastructure-securitymodel-serving-securitycontainer-ai-workload-securitysecrets-in-prompts-detection
Runtime/deployment
model-watermarking-fingerprintinginference-api-abuse-preventionmodel-caching-security
Agentic/multi-agent
agent-memory-poisoningtool-schema-validation-securityhuman-in-the-loop-bypass
Data pipeline
training-data-poisoningdataset-supply-chain-securitysynthetic-data-security
Identity/authz
ai-agent-identity-authzmulti-tenant-model-isolation
Evasion/detection
ai-content-authenticityoutput-fingerprinting-detectionai-assisted-social-engineering
Emerging
llm-dos-resource-exhaustionmultiagent-coordination-attacksbrowser-agent-security
Compliance/governance
ai-audit-loggingai-red-team-programthird-party-model-riskai-privacy-pii-compliance
Recommended Starting Points
New to AI security review — start here:
core-llm-prompt-security— prompt injection and output validationrag-security— retrieval poisoning and boundary enforcementtool-use-execution-security— agent tool call authorizationai-governance-and-incident-response— enterprise ops baseline
Add framework depth:
langchain-rag-security,llamaindex-rag-security,haystack-rag-securityautogen-multiagent-security,crewai-agent-securityollama-security,litellm-proxy-securityguardrails-ai-security,nemo-guardrails-security
Running a red team exercise:
prompt-injection-red-teaming— methodology and CI integrationjailbreak-taxonomy— technique catalog and detection signaturesadversarial-robustness— input normalization and classifier hardening
Privacy and compliance review:
ai-privacy-pii-compliance— GDPR/CCPA, DPIAs, data subject rightsai-audit-logging— tamper-proof event logging schemathird-party-model-risk— vendor DPA, behavioral monitoring, fallback
Repository Layout
skills/ 58 SKILL.md files, one directory each
references/ severity-and-reporting, test-patterns, framework-mappings
tests/adversarial-fixtures/ 12 JSON fixtures for prompt injection variants
red-team-scripts/
scripts/validate_repo.py manifest consistency and fixture checker
skills.json machine-readable skill indexRepo Guarantees
skills.jsonis the machine-readable index — every skill registered with controls and severity- every skill has
last_reviewedfrontmatter - every control has a severity (
critical,high,medium,low) python3 scripts/validate_repo.pyvalidates all 58 skills and fixtures
Key Docs
- CONTRIBUTING.md: how to add or classify a skill
- ROADMAP.md: what is shipped and what is planned
- references/framework-mappings.md: OWASP LLM Top 10 and MITRE ATLAS crosswalk
- references/test-patterns.md: repeatable attack categories
License
Released under the MIT License.
