Skip to content

mjcramerz/security-controls

v1.1.0

Use this plugin for application, host, and supply-chain security control workflows.

Security Controls task routing

Read this plugin only when its listed skills match the current task. Discover the actual client tools, account access and permission requirements before invoking anything. Treat this directory as bundled source, not proof of an installed or authenticated integration.

Select one entrypoint

SkillApply it to
appsec-hardeningApply application security hardening controls such as input validation, authn/authz checks, safe subprocess patterns, security headers, and abuse-rate defenses
bws-localUse this skill for install, configure, and rotate Bitwarden Secrets Manager CLI (bws) for local Debian systems with keyring-backed secret storage
secops-aideConfigure AIDE file-integrity monitoring rules, baselines, and scheduled verification runs
secops-auditdConfigure auditd rules and log capture policies with safe performance tradeoffs and compliance alignment
secops-crowdsecConfigure CrowdSec collections, parser sources, and bouncer integration with safe enforcement defaults
secops-supply-chainHarden software supply-chain controls through dependency pinning, lockfile discipline, SBOM generation, and CI enforcement
secops-usbguardConfigure USBGuard device authorization policies and rule sets for USB attack surface reduction
security-best-practicesPerform language and framework specific security best-practice reviews and suggest improvements
security-ownership-mapAnalyze git repositories to build a security ownership topology (people-to-file), compute bus factor and sensitive-code ownership, and export CSV/JSON for graph databases and visualization
security-threat-modelUse this skill for repository-grounded threat modeling that enumerates trust boundaries, assets, attacker capabilities, abuse paths, and mitigations, and writes a concise Markdown threat model

Preserve the integration boundary

Read only the references required by the selected skill. Inspect bundled scripts before execution; retain their argument and output contracts. Keep credentials and private payloads out of examples, logs and ambient hook context.

Do not install, enable, trust, publish or update a remote integration merely because you edit these files. Keep canonical and authorized bundled mirrors coherent, preserve existing resource paths and license notices, and report the checks you actually performed. Local packaging does not assert vendor endorsement.