security-baseline - Security Baseline Checklist
Run nine authoritative security checks covering CSP, OAuth, PKCE, JWKS, CSRF, MCP auth, URL redaction, and backtrace policy.
Tags
Updated: 2026-05-09Capabilities
Typical Inputs
Typical Outputs
What this skill does
- verify security headers
- check OAuth callback flow
- validate PKCE state storage
- test JWKS caching
- enforce CSRF defenses
- check MCP auth methods
- verify stdio auth policy
- redact sensitive URLs
- check error response policies
Inputs
- changed files
- spec.md Security baseline section
- configuration files
- environment variables
Outputs
- violation report
- flagged issues
- HIGH violations count
- sections OK status
Requirements
- security-reviewer preload
- spec.md access
- Rust codebase access
