check-security
Looks at what a change could do to login, personal data, or a service outside us, and returns pass, pass-with-conditions, or fail. Use when a change touches auth, personal data, or an outside API, or when the security lead has to sign off. Triggered by "is this safe", "security check", "we are adding a login", or "we are storing personal data".
Pinned to revision ed00ad05b6bf, so it is the text this page describes rather than whatever the author pushed since.
Files
- skills/check-security/SKILL.md
- skills/check-security/references/domain-playbooks.md
- skills/check-security/references/security-gate.md
- skills/check-security/references/security-review-template.md
- skills/check-security/references/threat-model.md
Every link opens the file at its source, pinned to the revision this page describes.