authorized-security-router

Installation
SKILL.md

Authorized Security Router

Route security work before acting. This skill is for authorized defensive analysis, triage, and reporting. It is not an exploitation, evasion, credential, persistence, phishing, or C2 playbook.

Scope Gate

Before selecting a route, establish:

  • authorization: own system, internal review, client-approved scope, CTF/lab, or inspect-only public repository/artifact review;
  • target boundary: repository, app, package, binary, API, URL, firmware image, sample hash, or document set;
  • action level: inspect-only, local static analysis, local sandbox analysis, browser verification, report-only, or remediation planning;
  • prohibited actions: no unauthorized access, no destructive testing, no live exploitation, no credential extraction, no persistence, no evasion, no phishing, no C2, no scope expansion.

Public review means inspect-only review of public repositories or static artifacts. It does not authorize interacting with public URLs, third-party apps, production APIs, login flows, or browser-driven security testing. URL, app, API, and browser-facing security routes require own-system, client-approved, internal, or lab/CTF authorization.

If scope is unclear or the request asks for offensive execution, stop and ask for a safer authorized framing.

Allowed Routes

Installs
5
GitHub Stars
15
First Seen
Jul 10, 2026
authorized-security-router — markoblogo/abvx-agent-skills