security
Installation
SKILL.md
Security: Think Like an Attacker
Core Principle
Defense in Depth + Least Privilege. Layer multiple controls. Grant minimum permissions. Assume every layer can fail.
Security Mindset
Six Questions (Every Feature)
- Who can access this? (Authentication)
- Are they allowed to? (Authorization)
- Can they see more than they should? (Data exposure)
- Can they do more than they should? (Privilege escalation)
- Can they break it for others? (Denial of service)
- Will we know if they do? (Audit logging)