security
Installation
SKILL.md
Security
When to use
Invoke after system-design has approved a design and before implementation skills generate code, schemas, or infrastructure that hardens trust boundaries. Use it whenever a system handles sensitive or regulated data, crosses tenant or org boundaries, integrates third parties, or sits under a regulatory regime.
Do not use for security-tool configuration (route to the relevant implementation skill), CVE triage or specific vulnerability fixes, penetration testing, incident response (use operations and reliability), or compliance audit evidence collection (use operations).
Inputs
Required:
- Approved
system-design.mdand the relevant ADRs. - The security scope in question: the system, a new surface (new API, new integration, new tenant model), or a change that crosses a trust boundary.
- Data inventory: what data the system processes, stores, transmits, or derives.
Optional: