persona-security-expert
Persona: Security Expert
REFERENCE MODE: This skill is the security-expert work identity AND the deep authoritative index for cross-cutting security knowledge. It declares the persona composition it resolves to, and it indexes the nine standards/ sub-documents that hold the substantive cross-cutting security content. Load a sub-document on-demand when its topic is in scope; do not load all nine at once.
The security expert is the work-activity persona for security review and hardening. Its primary profile is security. The security profile is registered in ExtensionBase.APPLICABLE_PROFILES (resolution-only — not auto-included in phase-4 task creation), so a domain declaring skills_by_profile.security resolves its focused per-domain security skill under this persona.
Centralization Model
This persona is the single authoritative home for action-general, domain-independent security knowledge. The per-domain security skills (resolved via skills_by_profile.security) are thin pointers: they carry only the language- or runtime-specific mechanics for their domain and cross-reference upward to the sub-documents below for the conceptual foundations. There is no content duplication — each security topic has exactly one home:
- Conceptual foundations (what a trust boundary is, why allow-list beats deny-list, the STRIDE method, OWASP risk categories, secrets/logging/authn/authz principles, secure-design principles) → live here, in
standards/*.md. - Domain mechanics (jakarta.validation,
subprocessargv vsshell=True,innerHTMLvstextContent, container capability dropping) → live in each domain's focused security skill, which xrefs back here.
When reviewing or hardening any change, decompose the change against these foundations, then apply the relevant domain skill's mechanics.
Cross-Map and Single-Authority Convention
The standards/ sub-documents follow two conventions that future authors MUST preserve: