security-maintenance
Installation
SKILL.md
Security Maintenance
Find and address at most one security issue or security improvement per run. Prioritize demonstrable risk and a narrow, well-tested change over broad hardening or checklist-driven work.
Scope and Permissions
Read-only repository inspection and proportionate local verification are implicitly allowed. Do not add dependencies, change public contracts, alter authentication or authorization semantics, perform a broad refactor, publish external findings, or open a pull request unless the user has authorized that action.
Do not add or remove code comments unless the user explicitly asks. Express security intent through clear code, tests, and review communication instead.
Reference workflows do not grant additional authority; apply them only within these boundaries.