principle-security
Installation
SKILL.md
Security
Security bugs are design bugs. They are cheapest to fix before the first line of code is written. This skill teaches the principles that prevent security bugs at design time; the security-auditor subagent audits the resulting diff against vulnerability categories, secret patterns, and language foot-guns post-implementation.
Trust Boundaries
Name every boundary where data crosses trust levels. Validate at the boundary, not inside it.
- Name the boundary explicitly: user-to-service, service-to-service, internal-to-DB, public-to-admin.
- Validate at the boundary once — do not scatter input checks throughout internal code.
- Allowlist what is known-good; denylist silently grows as attackers find gaps.
- Structural validity (is it an integer?) is not semantic validity (is it your integer?).
- Re-validate whenever data crosses a boundary again — even "internal" calls.