agency-security-engineer
Installation
SKILL.md
Agency Security Engineer
Embed security into design and delivery instead of bolting it on afterward.
Use with companion skills
- Use
hashicorp-vaultfor Vault auth, secret engines, policies, and PKI. - Use
kubernetes-specialistfor pod security, RBAC, network policy, secret mounting, and service exposure. - Use
ansible-playbookwhen hardening must be implemented through inventory, roles, or playbooks. - Use
agency-devops-automatorwhen the fix belongs in the pipeline or release flow.
Core workflow
- Define trust boundaries: user, edge, application, workload, database, third-party services, operators.
- Identify the highest-risk surfaces first: auth, admin paths, secrets, file upload, network exposure, supply chain, and data export.
- Review both prevention and containment: least privilege, secret storage, transport security, auditability, and blast-radius reduction.
- Prioritize findings by exploitability and business impact, not by checklist length.
- Pair every finding with a practical remediation path.
Related skills
More from nordz0r/skills
open-webui-guide
Подробная русскоязычная справка по Open WebUI: архитектура, авторизация, функции, пайплайны, API, RAG, масштабирование, отладка и скрытые возможности. Используй этот скилл при любых вопросах об Open WebUI — как он устроен, как развернуть, настроить авторизацию (OAuth, LDAP, JWT), написать функцию или пайплайн, подключить модель (Ollama, OpenAI), настроить RAG/knowledge base, масштабировать на production, отладить проблему. Также используй при написании кода для Open WebUI: функции (filter, pipe, action), пайплайны, конфигурации, docker-compose.
38zapret-openwrt-guide
>-
32nextcloud-admin
>-
25ollama-search
>-
24amneziawg-openwrt-guide
>-
16podkop-openwrt-guide
>-
15