Review Blumark24 OS security, permissions, privacy, Saudi PDPL alignment, and Zero Trust controls. Use for authentication, authorization, tenant isolation, sensitive data, and…
Use when designing or reviewing Server Actions: the 'use server' directive contract, how a server-side function becomes invokable from the browser without an API route, form…
The durable documentation set that makes an AI-built (vibe-coded) app reviewable before shipping. A small core every app needs — architecture, user/permission flows, permissions,…
Security audit and vulnerability scanning for AI agent skills before installation. Detects prompt injection in SKILL.md files, dangerous code patterns (eval, exec, subprocess),…
Audit and validate D&D 5e 2024 monster stat blocks for mechanical correctness, format conformity, and internal consistency.
Domain knowledge for the tachi orchestrator agent: input format detection, DFD classification, trust boundary notation, STRIDE-per-Element dispatch rules, coverage requirements…
Shared reference for the Tauri cluster: the v2 security model (capabilities → permissions → scopes), the IPC trust boundary and command contract, the process/runtime model, CSP,…
Run an extremely strict security audit for auth flaws, injection vectors, secrets exposure, broken access control, and boundary validation failures.
Use when reviewing a change, feature, or design for security — walk Shostack's four questions and STRIDE across every trust boundary of THIS stack, not a generic checklist.
Compares Trailmark code graphs at two source code snapshots (git commits, tags, or directories) to surface security-relevant structural changes.
Expert guide for Zero-Trust Secret Management (Infisical, HashiCorp Vault, Doppler), automated API key rotation, and environment security / Panduan ahli manajemen rahasia…
A change touching Zod — `z.object`, `z.infer`, `safeParse`, `z.codec`, `z.coerce`, `z.brand`, `z.discriminatedUnion`, `.refine`, `.transform`, `zodResolver`, `z.toJSONSchema`,…
ASK (Agent Security Framework) compliance reviewer — ASK 2026.04 (27 tenets). Use this skill whenever the user wants to: review code, specs, architecture, or designs for ASK…
This skill should be used when performing a security review or audit of Compact smart contract code, or when reasoning about Compact's security threat model.
Use this skill when working with ThreatLocker computer groups — the policy-scoping boundary that determines which allow/deny rules apply to which endpoints.
Use this skill before enabling Microsoft 365 Copilot for any user population. Runs an oversharing assessment, applies sensitivity labels and DLP controls, validates permissions…
Transform legacy system representations into secure cloud-native patterns, covering monolith decomposition, on-prem-to-cloud threat translation, sidecar and API-gateway security,…
Define the trust boundaries and perimeters within an infrastructure architecture to isolate sensitive components.
When adding a new skill to the `dev-security/claude-rules/skills/` pack, or when substantively revising an existing skill's structure or frontmatter, apply the pack's established…
This skill should be used when scanning Claude Code skills or agent files for advisory security risks: code-execution, prompt-injection, supply-chain, filesystem-boundary,…
World-Class Technology & Data Playbook. Use for: software development best practices, IT infrastructure design, cybersecurity strategy, data analytics, business intelligence,…
AI実行環境のシークレット境界設定。settings.json permissions.denyルールを生成し、シークレットへの事故的アクセスを防止する。