tjboudreaux/cc-plugin-engineering-excellence · Archived

eng-security-safety

Apply proactive threat modeling, least-privilege design, and safety guardrails before delivering any code or infrastructure change.

First seen Mar 1, 2026

Installation

$ npx skills add tjboudreaux/cc-plugin-engineering-excellence --skill eng-security-safety

Stronger alternatives

This repository is archived — consider an actively maintained alternative.

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from tjboudreaux/cc-plugin-engineering-excellence · top by installs.

npx skills add tjboudreaux/cc-plugin-engineering-excellence

Browse all from tjboudreaux/cc-plugin-engineering-excellence

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Repository health

Stars 1
License LICENSE
Default branch main
Open issues 0
Status Archived

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 2,016 B
  • docs SUMMARY.md 158 B

History

  1. First seen on skills.sh
  2. First recorded snapshot · 2 installs

SKILL.md

Security and Safety Mindset

Intent

  • Treat every change as a potential attack surface or failure amplifier.
  • Ensure data classification, secret handling, and permission scopes stay compliant.
  • Bake safety checks (rate limits, input validation, monitoring) into the design, not after.

Baseline Checklist

  1. Threat model quickly: Who could abuse this surface? What capabilities do they need? What happens if they succeed?
  2. Data stewardship: Classify data touched (PII, payments, assets) and enforce encryption, retention, and locality rules.
  3. Access + identity: Validate authn/authz paths, key rotation, wallet signatures, and privilege escalation barriers.
  4. Dependency hygiene: Pin versions, verify licenses, review changelogs, and prefer audited libraries/contracts.
  5. Secrets + config: Never log secrets; store them in the project’s approved secret manager. Guard env var usage.

Workflow

  1. Enumerate entry points (mobile UI, API, smart contract, admin tools) and list unchecked inputs.
  2. Define validation layers: schema-level, business-level, and environment-level (e.g., chain ID, platform version).
  3. Ensure every state change is reversible or compensatable (feature flags, contract pausing, migration guards).
  4. Instrument detection: structured logs, metrics, or on-chain events that can surface abuse or regressions fast.
  5. Document explicit “never do” actions (e.g., disable signature checks, bypass paywalls) inside the PR/issue notes.

Verification

  • Run the project’s security/static analysis tooling (linters, contract analyzers, mobile scanners) and fix findings.
  • Peer review the threat model summary; confirm secrets and keys are absent from diffs/logs.
  • Validate abuse cases end-to-end (invalid payloads, replayed signatures, abusive traffic) before shipping.