I am a cloud security and AI agent security engineer. I build tooling for AWS guardrails, Microsoft 365 governance, MCP servers and Claude Code skills. Everything below is open source and each repository stands on its own.
| Repository | What it is |
|---|---|
| aws-security-skills | AWS security skills for Claude Code: account audit, SCP guardrails, blast-radius landing zones, IAM least privilege, Security Hub triage. |
| repo-engineering-skills | Repository engineering skills for Claude Code: docs checked against the code, audits where every finding cites a line, agent context files that say only what code cannot. |
| m365-governance-skills | Microsoft 365 governance skills for Claude Code: Entra ID posture review, Intune baseline check, Graph permission preflight, Teams and group sprawl, access review pack. |
| claude-dev-skills | Claude Code skills for everyday development: code review, refactoring, debugging, CI and containers, data and APIs, documentation and security basics. |
| agent-security-skills | Claude Code security plugin and agent skills for securing LLM agents: threat modelling, configuration audits, prompt injection review, MCP server review, incident lookup. |
| Repository | What it is |
|---|---|
| dev-mcp-servers | Ten small MCP servers for everyday development and security checks. |
| mcp-server-template | Secure MCP server template in TypeScript and Python, safe by default. |
| mcp-tools-lint | Lint MCP tool schemas and annotations before clients reject them. |
| mcp-auth-doctor | Diagnose OAuth discovery problems on remote MCP servers. |
| mcp-egress | Record every host an MCP server contacts, per tool, and fail CI on new ones. |
| claude-mcp-allow | Least-privilege Claude Code permission rules for MCP tools, generated from their annotations. |
| Repository | What it is |
|---|---|
| agent-threat-model | Threat modeling for AI agents: describe the system in YAML, get a STRIDE and OWASP Agentic threat model. |
| agent-config-audit | Audit AI agent configuration files for security risks. |
| agentic-semgrep-rules | Semgrep rules for AI agent code in Python, TypeScript and JavaScript. |
| security-actions | GitHub Actions for AI agent and supply chain security checks. |
| cc-hooks | Typed Python SDK and offline test runner for Claude Code hooks. |
| llms-txt-gen | Generate llms.txt for any docs site or repository. |
| Repository | What it is |
|---|---|
| ai-agent-incidents | An open dataset of AI agent and LLM security incidents, with a browsable site. |
| awesome-agent-security | Curated list of AI agent security tools, papers and datasets. |
Packages: published packages are listed at github.com/basitalisandhu?tab=packages.
| Project | Latest release | Published |
|---|---|---|
| aws-security-skills | v0.1.0 | 2026-10-04 |
| repo-engineering-skills | v0.1.0 | 2026-10-04 |
| m365-governance-skills | v0.1.0 | 2026-10-04 |
| claude-dev-skills | no public release yet | |
| agent-security-skills | no public release yet | |
| dev-mcp-servers | v0.1.0 | 2026-10-04 |
| mcp-server-template | v0.1.0 | 2026-10-04 |
| mcp-tools-lint | v0.1.0 | 2026-10-04 |
| mcp-auth-doctor | v0.1.0 | 2026-10-04 |
| mcp-egress | v0.1.0 | 2026-10-04 |
| claude-mcp-allow | v0.1.0 | 2026-10-04 |
| agent-threat-model | v0.1.0 | 2026-10-04 |
| agent-config-audit | v0.1.0 | 2026-10-04 |
| agentic-semgrep-rules | no public release yet | |
| security-actions | no public release yet | |
| cc-hooks | v0.1.0 | 2026-10-04 |
| llms-txt-gen | v0.1.0 | 2026-10-04 |
| ai-agent-incidents | no public release yet | |
| awesome-agent-security | no public release yet |
- GitHub: @basitalisandhu
- Questions about a project: open an issue in that project's repository.
