Skip to main content
GitHub repository

kc-secure-repo-template

kc-secure-repo-template contains 8 collected skills from CaseyLabs, with repository-level occupation coverage and site-owned skill detail pages.

skills collected
8
Stars
9
updated
2026-04-28
Forks
0
Occupation coverage
2 occupation categories · 100% classified
repository explorer

Skills in this repository

pr-draft-summary
software-developers

Draft a concise pull request handoff after substantive repository changes are finished or ready for review. Trigger when wrapping up code, test, script, workflow, release, security, documentation-with-behavior-impact, or template customization changes and the user needs a PR title/body grounded in the real diff, commits, and validations run. Do not use for tiny chat-only answers, speculative plans, or changes that are not ready for PR handoff.

2026-04-28
github-hardening
information-security-analysts

Use when updating or reviewing GitHub-side hardening guidance for derived repositories, including required settings, rulesets, scanning, review protections, and workflow permissions. Use terraform-hardening instead for Terraform-backed changes under config/infra. Do not use for ordinary in-repo implementation changes unless the task is primarily about documented GitHub controls.

2026-04-27
language-profile-guidance
software-developers

Use when adding or revising optional language-specific guidance for Go, Node.js, SQL, or small polyglot derived repositories without bloating the generic template. Keep language behavior optional. Do not use for generic template policy, routine validation, GitHub-settings-only work, or release-integrity-only work.

2026-04-27
release-integrity
information-security-analysts

Use when reviewing or improving this template's release-integrity story, including artifact verification, SBOMs, attestations, vulnerability scanning, signing guidance, and release-workflow safety. Do not use for general CI validation, GitHub-settings-only work, or unrelated template customization.

2026-04-27
repo-adaptation
software-developers

Use when adapting or customizing this repository to meet the needs of the source code under `src/`, including language and framework needs, dependencies, runtime behavior, Docker, Makefile targets, and customization surfaces. Do not use for routine bug fixes, small refactors, pure workflow validation, GitHub-settings-only work, or release-integrity-only work.

2026-04-27
terraform-hardening
information-security-analysts

Use when changing or reviewing the Terraform-backed GitHub repository hardening workspace under config/infra, including provider pins, rulesets, default branch protection, required checks, secret scanning, Dependabot security updates, token handling, plan/apply behavior, and infra documentation. Do not use for ordinary app code, generic release integrity, generic template adaptation, or non-infra GitHub Actions changes unless they directly affect hardening expectations.

2026-04-27
workflow-validation
software-developers

Use when validating repository workflows after changes to Docker-first Makefile targets, Dockerfiles, scripts, CI, release packaging, smoke tests, or documentation alignment. Do not use for repo redesign, GitHub-policy-only changes, or instruction-only skill edits with no workflow impact.

2026-04-27
security-review
information-security-analysts

Manual-only skill. Use ONLY when the user explicitly invokes: $security-review Never select this skill via semantic matching.

2026-04-24