Skip to main content

security-engineering

星标10
分支2
更新时间2026年6月5日 16:11

Application security design and threat-informed engineering. Use for authentication and authorisation architecture (OAuth2, JWT, RBAC, ABAC), OWASP Top 10 vulnerability analysis, secrets management (Vault, AWS Secrets Manager, environment isolation), input validation patterns, secure API design, SQL injection and XSS prevention, and security-aware code review. Trigger phrases: "secure this endpoint", "design an auth system", "review this for security vulnerabilities", "how do I store secrets", "implement RBAC". NOT for network/infrastructure security (firewalls, VPNs, WAF config) — those belong in cloud-infrastructure. NOT for compliance auditing (SOC2, GDPR gap assessments) — that requires a compliance specialist. NOT for penetration testing or red-teaming — this skill is for defensive engineering, not offensive exercises.

安装

用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。

文件资源管理器
3 个文件
SKILL.md
readonly