security-ux
Build security interfaces that earn user trust through clarity, not intimidation. The goal is to make users feel safe and in control, not punished for security requirements.
Consult the authentication and account recovery reference for sign-in, MFA, session expiry, password UX, and recovery-stack guidance. Consult the permissions and roles UX reference for role editors, request-access flows, access-denied recovery, and risky permission changes. Consult the interface honesty reference for assertive UX language, honest progress and consent copy, and trust-preserving product behavior. Consult the error recovery reference for what happens after security-related failures.
MANDATORY PREPARATION
Users start this workflow with /security-ux. Once this skill is active, load $frontend-design — it contains design principles, anti-patterns, and the Context Gathering Protocol. Follow that protocol before proceeding — if no design context exists yet, you MUST load $setup first. Additionally gather: what threat model the product faces, what security features are already implemented, and where users currently feel confused or anxious about security.
Assess Security UX Needs
Identify where security and user experience intersect: