Why it exists
Hiding a button does not stop a direct request. This skill takes the agent from product policy to the routes, queries, writes, and tests that actually protect an operation.
Its scope stays proportional to the change: it reviews sensitive boundaries without turning every visual task into a full audit or replacing professional security review.
What it reviews
- Roles, permissions, and alternate paths to the same action.
- Isolation by person, organization, and resource ownership.
- Sessions, files, and operations with partial effects.
- Limits before expensive work begins.
- Direct unauthorized requests and their lack of side effects.
- The allowed case after the correction is applied.
A real shift-rotation case
During the implementation of a multi-tenant shift-rotation module, an initial functional version passed its positive cases but left four boundaries uncovered: a missing read permission, cross-organization enumeration, unbounded input, and an out-of-range starting index.
Reviewing the change with the skill turned those omissions into specific corrections and eleven tests covering both side-effect-free rejection and the authorized flow.
The skill provides reusable criteria. It does not add a security barrier by itself or guarantee that a model will apply every instruction correctly.
Installation
Install it from the published repository with the Skills CLI.
pnpm dlx skills add elpeakyblinder/security-skill --skill security-regression-guard Run the command from the project directory where you want to use it.