principle-security

Installation
SKILL.md

Security

Security bugs are design bugs. They are cheapest to fix before the first line of code is written. This skill teaches the principles that prevent security bugs at design time; the security-auditor subagent audits the resulting diff against vulnerability categories, secret patterns, and language foot-guns post-implementation.

Trust Boundaries

Name every boundary where data crosses trust levels. Validate at the boundary, not inside it.

  • Name the boundary explicitly: user-to-service, service-to-service, internal-to-DB, public-to-admin.
  • Validate at the boundary once — do not scatter input checks throughout internal code.
  • Allowlist what is known-good; denylist silently grows as attackers find gaps.
  • Structural validity (is it an integer?) is not semantic validity (is it your integer?).
  • Re-validate whenever data crosses a boundary again — even "internal" calls.

Authentication is Not Authorization

Installs
2
GitHub Stars
2
First Seen
Jun 10, 2026
principle-security — lugassawan/swe-workbench