authoring-security-skills

Installation
SKILL.md

Authoring Security Skills

A skill earns its context budget by carrying what the model would otherwise get wrong. The model already knows what nmap -sV does. It does not reliably hold the discipline — trace to demonstrated impact before reporting, preserve before remediating, refuse to ship a rule never tested against production noise.

That judgment is the deliverable. Commands are scaffolding around it.

When to Use

  • Adding a new skill to secskills-offense, -defense, or -core
  • Splitting an overloaded skill or merging two that overlap
  • Fixing a skill that loads for the wrong requests, or fails to load for the right ones
  • Resolving a failure from validate.py, sync_attack.py, or run_evals.py

When NOT to Use

Installs
22
GitHub Stars
146
First Seen
Jul 31, 2026
authoring-security-skills — trilwu/secskills