authoring-security-skills
Installation
SKILL.md
Authoring Security Skills
A skill earns its context budget by carrying what the model would otherwise get
wrong. The model already knows what nmap -sV does. It does not reliably hold
the discipline — trace to demonstrated impact before reporting, preserve
before remediating, refuse to ship a rule never tested against production noise.
That judgment is the deliverable. Commands are scaffolding around it.
When to Use
- Adding a new skill to
secskills-offense,-defense, or-core - Splitting an overloaded skill or merging two that overlap
- Fixing a skill that loads for the wrong requests, or fails to load for the right ones
- Resolving a failure from
validate.py,sync_attack.py, orrun_evals.py