kc-secure-repo-template
يحتوي kc-secure-repo-template على 8 من skills المجمعة من CaseyLabs، مع تغطية مهنية على مستوى المستودع وصفحات skill داخل الموقع.
Skills في هذا المستودع
Draft a concise pull request handoff after substantive repository changes are finished or ready for review. Trigger when wrapping up code, test, script, workflow, release, security, documentation-with-behavior-impact, or template customization changes and the user needs a PR title/body grounded in the real diff, commits, and validations run. Do not use for tiny chat-only answers, speculative plans, or changes that are not ready for PR handoff.
Use when updating or reviewing GitHub-side hardening guidance for derived repositories, including required settings, rulesets, scanning, review protections, and workflow permissions. Use terraform-hardening instead for Terraform-backed changes under config/infra. Do not use for ordinary in-repo implementation changes unless the task is primarily about documented GitHub controls.
Use when adding or revising optional language-specific guidance for Go, Node.js, SQL, or small polyglot derived repositories without bloating the generic template. Keep language behavior optional. Do not use for generic template policy, routine validation, GitHub-settings-only work, or release-integrity-only work.
Use when reviewing or improving this template's release-integrity story, including artifact verification, SBOMs, attestations, vulnerability scanning, signing guidance, and release-workflow safety. Do not use for general CI validation, GitHub-settings-only work, or unrelated template customization.
Use when adapting or customizing this repository to meet the needs of the source code under `src/`, including language and framework needs, dependencies, runtime behavior, Docker, Makefile targets, and customization surfaces. Do not use for routine bug fixes, small refactors, pure workflow validation, GitHub-settings-only work, or release-integrity-only work.
Use when changing or reviewing the Terraform-backed GitHub repository hardening workspace under config/infra, including provider pins, rulesets, default branch protection, required checks, secret scanning, Dependabot security updates, token handling, plan/apply behavior, and infra documentation. Do not use for ordinary app code, generic release integrity, generic template adaptation, or non-infra GitHub Actions changes unless they directly affect hardening expectations.
Use when validating repository workflows after changes to Docker-first Makefile targets, Dockerfiles, scripts, CI, release packaging, smoke tests, or documentation alignment. Do not use for repo redesign, GitHub-policy-only changes, or instruction-only skill edits with no workflow impact.
Manual-only skill. Use ONLY when the user explicitly invokes: $security-review Never select this skill via semantic matching.