lucidchart-security-basics
Installation
SKILL.md
Lucid Integration Security Baseline
Overview
Establish least privilege, safe data handling, trustworthy package boundaries, and auditable operations for the exact Lucid integration surface.
Prerequisites
- Architecture and data-flow inventory with classifications and owners
- Credential/principal and extension-scope inventory
- Repository, artifact, deployment, logging, retention, and incident evidence
Tool Discipline
Use Read, Glob, and Grep for bounded static inspection, WebFetch for current Lucid security contracts, and Write or Edit only for approved local remediation and redacted reports.
Current Contract
Lucid exposes multiple credential classes, operation-specific scopes/headers, Standard Import archives, editor-extension scopes, and optional connector runtimes. Each creates distinct trust boundaries; an extension bundle is not a safe place for confidential credentials.