
Security News
Insecure Agents Podcast: How to Keep AI Agents From Bypassing Security Controls
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.
Hostile first-reader pass on anything shipped, deemed done, or ready to ship. An agent with the skill writes the critique.
An installable skill for AI agents.
Check whether a newcomer can understand and use what you are about to ship.
Cold-eye is a readiness pass on anything shipped, deemed done, or ready to ship. An agent reads the skill and writes a critique. Verdict first, then a ranked list. The subject does not change.
Get started: pick the agent, install the skill, then run the sample checklist at coldeye.dev/docs/install.
Claude.ai without project files is not a supported first-use route. The install page lists current host limits.
Site: coldeye.dev
You wrote: “Install the package and launch the app.”
Cold-eye finds: the guide names the package but never gives the launch command. A new user cannot finish setup from the instructions given.
You get a ranked finding in the critique file:
**Verdict:** close
1. **F-001** · test 2 · invented
> Install the package and launch the app.
Cold reader: installs the package, then guesses a launch command or stops.
Put: The exact launch command on the next line, and what the reader sees when the app is running.
The guide itself is unchanged.
Save until-ready.md (or the checklist below), then ask:
Use Cold-eye on
until-ready.md. Follow the installed Cold-eye skill. Write the critique. Leave the checklist unchanged.
# Review until ready
Fictional procedure for desk-stamp notes. Labeled example.
1. Open `notes.md`.
2. Read every section.
3. Write findings next to the file as `notes.review.md`.
4. Repeat the review until ready.
The critique lands in until-ready.cold-eye.md. The checklist should be
unchanged. A finding should point at step 4, the unresolved “until
ready” condition. Wording varies by model. A critique alone does not
prove the skill loaded: check the agent's skill list, or ask it to
quote the first heading of SKILL.md.
A writable workspace is required. Package coldeye, skill folder
cold-eye.
npm supplies the skill files. It does not register the skill with the agent.
pnpm add -D coldeye
Copy node_modules/coldeye/skills/cold-eye/ into the same destination
the Get started page names for
your agent.
Updating the npm dependency does not refresh a folder you already copied. Copy again after you bump the package.
MIT. Copyright Catalyst Forge LLC.
FAQs
Hostile first-reader pass on anything shipped, deemed done, or ready to ship. An agent with the skill writes the critique.
The npm package coldeye receives a total of 970 weekly downloads. As such, coldeye popularity was classified as not popular.
We found that coldeye demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.