Agent Plugins Marketplace
← All plugins

pm-seatbelt

v1.0.0

Agent safety seatbelts: the pre-flight security checklists you run before an agent touches email, the browser, files, or goes autonomous — least-privilege reviews, prompt-injection spotting, and the blast-radius drill

Claude Code6 Skills

By Mohit AggarwalLicense: MIT1.4k GitHub starsUpdated 2 days ago

Directory evidence

Runtimes
Claude Code
Parsed components
6 skill or MCP entries
Source updated
Oct 4, 2026
Manifest status
Canonical path parsed

The directory validates manifest shape and source location. It does not execute the plugin or provide a security endorsement. Review the indexing methodology →

Install pm-seatbelt for Claude Code

Installs for the current user
claude plugin marketplace add IchenDEV/agent-plugin-mkt
claude plugin marketplace update agent-plugin-marketplace
claude plugin install pm-seatbelt@agent-plugin-marketplace

Paste and run these commands in a terminal with Claude Code. They add and refresh the PluginsMP catalog, then install this plugin.

The installer fetches third-party code from the source repository shown on this page. This directory validates manifest structure and source location, but does not perform a security audit; review the manifest, components, and source before installing.

Get the source manually
git clone https://github.com/mohitagw15856/pm-claude-skills

Clone the source repository, then follow its setup instructions to add the plugin to a compatible client. The plugin root is plugins/pm-seatbelt/.

Plugin files

plugins/pm-seatbelt/
├── .claude-plugin/plugin.json
├── skills/blast-radius-drill/SKILL.md
├── skills/browser-agent-preflight/SKILL.md
├── skills/email-agent-preflight/SKILL.md
├── skills/file-access-preflight/SKILL.md
├── skills/injection-spotter/SKILL.md
└── skills/tool-permission-review/SKILL.md

Included Skills6

blast-radius-drillskills/blast-radius-drill/SKILL.md

Run the worst-case drill before an agent goes autonomous — the 'if this agent were fully hijacked right now, what's the damage' walk-through, the containment controls (caps, kill-switch, reversibility, isolation), and the recovery plan. Use when asked what's the worst my agent could do, run a blast-radius assessment, prepare for an agent going rogue, or am I ready to let this run unattended. Produces the worst-case walk-through, the containment controls, the reversibility audit, and the incident-recovery runbook.

browser-agent-preflightskills/browser-agent-preflight/SKILL.md

Run the pre-flight checklist before an agent drives a browser — the untrusted-web-content threat (every page is attacker-controllable), the credential and session-cookie exposure, the action-confirmation gates for purchases and posts, and the sandboxing that limits the damage. Use when asked let my agent browse safely, is it safe to give the agent computer/browser use, guardrails before the agent uses my browser, or review my browser agent's setup. Produces the sandbox decision, the content-injection defenses, the action gates, and the credential-isolation rules.

email-agent-preflightskills/email-agent-preflight/SKILL.md

Run the pre-flight checklist before an agent touches an inbox — the read-vs-send permission line, the injection-in-email-body threat, the send-guard rules, and the blast-radius limits that keep a compromised agent from mailing the company. Use when asked let my agent read/send email safely, set up guardrails before the agent touches my inbox, is it safe to give the agent email access, or review my email agent's permissions. Produces the permission tier, the injection defenses, the send-gate rules, and the incident kill-switch.

file-access-preflightskills/file-access-preflight/SKILL.md

Run the pre-flight checklist before an agent gets filesystem access — the scope boundary (which directories, read vs write), the secrets-exposure sweep, the destructive-operation gates, and the path-traversal and untrusted-file defenses. Use when asked let my agent access my files safely, is it safe to give the agent file/computer access, guardrails before the agent touches my filesystem, or scope down my coding agent's reach. Produces the scope boundary, the secrets sweep, the write/delete gates, and the untrusted-content rules.

injection-spotterskills/injection-spotter/SKILL.md

Spot prompt-injection in untrusted content before an agent acts on it — the anatomy of injected instructions across the channels attackers use (email, web, files, tool outputs, documents), the tell-list, and the safe-handling response. Use when asked is this content trying to hijack my agent, check this page or email or file for prompt injection, spot the injection, or why did my agent go off-task. Produces the injection verdict with quoted tells, the channel-specific patterns, and the safe-handling protocol.

tool-permission-reviewskills/tool-permission-review/SKILL.md

Review what an agent is actually allowed to do before you turn it loose — the tool-by-tool audit (each capability's blast radius), the least-privilege pass that removes what the task doesn't need, the dangerous-combination check, and the allow/ask/deny tiering. Use when asked review my agent's permissions, what can this agent actually do, lock down my agent's tools, or is this MCP/tool set safe to grant. Produces the permission inventory with blast radius, the least-privilege cuts, the dangerous-combo flags, and the allow/ask/deny assignments.

Plugin manifests1

plugins/pm-seatbelt/.claude-plugin/plugin.json
{
  "$schema": "https://anthropic.com/claude-code/plugin.schema.json",
  "name": "pm-seatbelt",
  "version": "1.0.0",
  "description": "Agent safety seatbelts: the pre-flight security checklists you run before an agent touches email, the browser, files, or goes autonomous — least-privilege reviews, prompt-injection spotting, and the blast-radius drill",
  "author": {
    "name": "Mohit Aggarwal",
    "email": "[email protected]"
  },
  "homepage": "https://github.com/mohitagw15856/pm-claude-skills",
  "license": "MIT",
  "keywords": [
    "security",
    "agent-safety",
    "prompt-injection",
    "least-privilege",
    "preflight"
  ]
}

If you maintain this plugin, link to this source-backed listing from your README so users can review its manifest and indexed components.

[pm-seatbelt on Agent Plugins Marketplace](https://pluginsmp.com/plugins/pm-seatbelt)