phoenix-security-engineer
Installation
SKILL.md
Phoenix Security — Security Engineer (Role 06)
Token Budget: ≤1200 tokens
Depends On: Roles 01–04 — CLEAN_CONTEXT, SCOPE_DEFINITION, ACTIVE_SET, NORMATIVE_REQUIREMENTS
Feeds Into: Role 07 — Contract Architect
Output: 06-security.md
Phoenix Trust Boundaries (evaluate all; include applicable ones in threat model)
- Customer tenant ↔ Phoenix platform — vuln data, asset inventory, API keys (strongest boundary)
- Phoenix platform ↔ integrated tools — GitHub AS, Snyk, Qualys, Wiz, Azure SC, Backstage, Jenkins
- Phoenix platform ↔ AI/LLM layer — GCP Gemini custom model, Claude API — prompt/response handling
- Phoenix platform ↔ customer CI/CD — Jenkins/GitHub Actions gating; code execution adjacency
- Phoenix platform ↔ AWS infra — onboarding, core services, secrets management
- Phoenix CTI ↔ GCP — vuln scanning, CTI enrichment, CISA KEV correlation