security
Installation
SKILL.md
Security
Use this skill to produce scoped, evidence-backed assessments and concrete remediation plans.
Core Principles
- State assumptions and confidence.
- Prefer root-cause fixes and defense in depth.
- Provide verification steps that are easy to run.
Intake (Ask Only What You Need)
- Question type: exploitable, severity, incident, design review, or fix validation.
- System boundary: repo/service, environment, and owner.
- Data at risk: credentials, PII, payments, IP, availability.
- Evidence: logs, scans, code, configs, timestamps, PoC.
- Constraints: time, testing limits, approvals.
If incident-like, ask for timeframe, indicators, and containment actions. If design review, ask for trust boundaries and intended auth model.