security - Security-First Design Enforcement
Enforces defense in depth, input validation, secure defaults, and OWASP best practices during design, planning, implementation, and code review to prevent vulnerabilities before they ship.
Tags
Updated: 2026-06-30Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Validate input at system boundaries
- Enforce authentication and authorization rules
- Check secrets management practices
- Apply defense in depth layers
- Verify secure default configurations
- Audit dependencies for known CVEs
- Prevent injection and XSS attacks
- Run security planning checklist
- Review code for security violations
- Capture security findings in backlog
Inputs
- Design documents or plans
- Source code for review
- Dependency list or lockfile
- OWASP Top 10 reference
Outputs
- Security review findings
- Security checklist results
- Backlog items for security issues
Requirements
- Integration with planning workflow
- Integration with code review workflow
- Optional backlog tracking system
