W Security

blockmatic/basilic-skills/skills/workflow/w-security

by blockmatic7e05e2abd052dc6b526e8a28e36d102d42bfd635No license1 starsListed Oct 9, 2026Updated Oct 9, 2026Repository updated 6 days ago

Review the change or tree against repository security docs and existing checks.

Instructions onlySecurity
AI-generated overview

Reviews code changes or a repository tree for security defects against existing security docs and scanners.

What it does
This skill guides a report-only security review of a change set or repository tree, anchored to the repository's own security documentation and existing scanners. It reads those docs first, then dispatches two to three read-only explorers over authentication/authorization, secret exposure, and input validation for the changed paths, and reconciles trigger and consequence for each suspected issue. It can run existing security scripts or CI jobs when authorized and records whether they passed, failed, or were not run, and it may apply fixes to the owning cause when the user authorizes them.
When to use it
Use it when a code change or repository tree needs a security review grounded in the project's documented security bar and existing checks. It fits pre-merge review, audit-style passes, and hardening work where findings should be reported rather than invented. It is not meant for teams without repository security docs, since it stops and asks instead of setting its own standard.
Requirements
Requires repository security documentation to exist, plus access to the changed paths and, when running checks, the project's security scripts or CI jobs (for example via package.json). It ships no scripts of its own and is instructions only. It may spawn read-only explorer subagents and, if fixes are authorized, edit code; policy changes are deferred to a human.

Find security defects relative to repository security docs and existing scanners. Do not invent CORS, encryption, password, or header policy. Stay report-only unless the user asked to fix.

  1. Read the repository security docs. If missing, stop and ask; do not invent a bar.
  2. Spawn 2–3 read-only explorers on authn/authz, secret/exposure, and input validation for the changed paths. Reconcile trigger and consequence yourself.
  3. Validate each suspected issue with a trigger and consequence. Skip invented CVEs and timings.
  4. If authorized, run existing security scripts or CI jobs from the docs or package.json. Record passed, failed, or not run.
  5. If fixes are authorized, change the owning cause. Policy changes need a human. Docs: /w-docs if behavior or commands changed.

Source and attribution

Source:blockmatic/basilic-skillsinskills/workflow/w-securityat commit7e05e2a

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal