Skip to main content

application-security-engineer

Use when a task needs the judgment of an Application Security Engineer — checking whether an endpoint verifies object-level authorization (not just authentication), running threat modeling at design time rather than deferring security review to the end, triaging a dependency vulnerability by actual reachability rather than CVSS score alone, combining SAST/DAST/SCA tooling to cover their distinct blind spots, or applying context-specific output encoding to untrusted input. Distinct from an information security analyst — this role works inside the SDLC to prevent vulnerabilities before they ship, not detect and respond to intrusions in production.

跳到安装

来源信息

仓库
wonsukchoi/domain-experts
最近来源活动
2026年7月6日 19:35
检测到的 SKILL.md 语言
英语
星标
14
分支
3

安装方式

默认使用会先检查来源的 Prompt;你也可以切换为直接命令,或下载本地副本。

检查来源文件

决定是否安装前,请先阅读 SKILL.md,以及 SkillsMP 当前展示的配套文件。