Skip to content

slight76/security-standards

v1.0.1MIT

Team security standards for developers and AI agents: application security, identity, CORS, secrets, threat modeling, CI/CD supply chain, dependencies and SBOM

security-standards

Team security standards for developers and AI agents: application security, identity, CORS, secrets, threat modeling, CI/CD supply chain, dependencies and SBOM.

Part of the Slight76 standards handbooks indexed at standards-marketplace. Written for a small team and its AI agents.

Documents

DocumentCoversRule prefixes
docs/security-architecture.mdSecurity design baseline: authentication and authorization on every operation, threat documentation, browser credential rules, sensitive data lifecycleSEC-001..004
docs/identity-standard.mdIdentity profiles, token audience validation, resource/tenant authorization, browser sessions, CSRF, no custom protocolsIAM
docs/cors-standard.mdSame-origin vs cross-origin decision, exact per-environment origin allow-lists, credentials, ASP.NET Core fragment, verification matrixCORS
docs/application-security-standard.mdThreat model scope, input validation, SSRF, uploads, rate limits, CSP, secrets and telemetry, webhooks, negative test matrixSEC-005..007
docs/secrets-management.mdWhere secrets live (user-secrets, .env, Fly.io, GitHub environments), nothing in git/images/logs, push protection, rotation, leak responseSECR
docs/threat-modeling-guide.mdLightweight STRIDE-per-boundary process, triggers, filling the template, mitigations mapped to rule IDsTM
docs/ci-cd-and-supply-chain-security.mdSHA-pinned actions, least-privilege permissions, OIDC and short-lived tokens, protected environments, trigger footguns, provenance attestationsSCS
docs/dependency-and-sbom-policy.mdLockfiles, Dependabot/Renovate cadence, vulnerability scanning, severity SLAs, CycloneDX SBOM per release, license allow-listDEP
templates/threat-model.mdThreat model table template used by the guide(template)

Read by task

See skills/security-standards/SKILL.md.

Install as an agent skill

AgentCommand
Copilot CLIcopilot plugin marketplace add Slight76/standards-marketplace then copilot plugin install security-standards@slight76-standards
GitHub CLI (any agent)gh skill install Slight76/security-standards security-standards --scope user --pin v1.0.0
Claude Code/plugin marketplace add Slight76/standards-marketplace then /plugin install security-standards@slight76-standards

Layout

PathPurpose
docs/Standards documents (frontmatter, applies-when, rule table)
catalog/catalog.jsonMachine-readable rules; externalDecisions points at historic ADRs
adr/Decisions local to this handbook
skills/security-standards/Agent skill and references
templates/Templates specific to this domain (shared ones live in the marketplace)

Validation: py ../standards-marketplace/tooling/validate.py --root .. License: MIT.