Skip to main content

security-engineering

Stars10
Forks2
UpdatedJune 5, 2026 at 16:11

Application security design and threat-informed engineering. Use for authentication and authorisation architecture (OAuth2, JWT, RBAC, ABAC), OWASP Top 10 vulnerability analysis, secrets management (Vault, AWS Secrets Manager, environment isolation), input validation patterns, secure API design, SQL injection and XSS prevention, and security-aware code review. Trigger phrases: "secure this endpoint", "design an auth system", "review this for security vulnerabilities", "how do I store secrets", "implement RBAC". NOT for network/infrastructure security (firewalls, VPNs, WAF config) โ€” those belong in cloud-infrastructure. NOT for compliance auditing (SOC2, GDPR gap assessments) โ€” that requires a compliance specialist. NOT for penetration testing or red-teaming โ€” this skill is for defensive engineering, not offensive exercises.

Installation

Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.

File Explorer
3 files
SKILL.md
readonly