Enterprise Security Skill
MANDATORY: Invoke docs-management First
STOP - Before providing ANY response about Claude Code enterprise security:
- INVOKE
docs-management skill
- QUERY for the user's specific topic
- BASE all responses EXCLUSIVELY on official documentation loaded
Skipping this step results in outdated or incorrect information.
Verification Checkpoint
Before responding, verify:
If ANY checkbox is unchecked, STOP and invoke docs-management first.
Overview
Central authority for Claude Code enterprise security. This skill uses 100% delegation to docs-management - it contains NO duplicated official documentation.
Architecture: Pure delegation with keyword registry. All official documentation is accessed via docs-management skill queries.
When to Use This Skill
Keywords: enterprise, managed-settings.json, enterprise managed policy, settings precedence, organizational policies, cloud execution security, IDE security, VS Code security, JetBrains security, devcontainer security, team security, audit logging, credential protection
Use this skill when:
- Configuring enterprise managed policies
- Understanding settings precedence
- Setting up organizational security standards
- Configuring cloud execution security
- Understanding IDE security considerations
- Setting up devcontainer security
- Implementing team security practices
Keyword Registry for docs-management Queries
Use these keywords when querying docs-management skill for official documentation:
Enterprise Managed Policies
| Topic |
Keywords |
| Overview |
"enterprise managed policy", "managed-settings.json" |
| File Locations |
"enterprise policy paths", "policy file locations" |
| Precedence |
"settings precedence", "enterprise policies precedence" |
| Unoverridable |
"unoverridable policies", "organizational restrictions" |
Cloud Execution Security
| Topic |
Keywords |
| Overview |
"cloud execution security", "isolated virtual machines" |
| Network Controls |
"network access controls", "cloud network security" |
| Credentials |
"credential protection", "cloud credential security" |
| Branch Restrictions |
"branch restrictions", "protected branches" |
| Audit Logging |
"audit logging", "security audit" |
| Cleanup |
"automatic cleanup", "cloud session cleanup" |
IDE Security
| Topic |
Keywords |
| VS Code |
"VS Code security", "IDE security VS Code" |
| JetBrains |
"JetBrains security", "IDE security JetBrains" |
| IDE Context |
"IDE-specific security", "extension security" |
DevContainer Security
| Topic |
Keywords |
| Container Isolation |
"devcontainer security", "container isolation" |
| Security Features |
"devcontainer security features", "container security" |
| Integration |
"devcontainer sandboxing", "container integration" |
Security Best Practices
| Topic |
Keywords |
| Team Security |
"team security", "organizational standards" |
| Sensitive Code |
"working with sensitive code", "security best practices" |
| Reporting Issues |
"reporting security issues", "HackerOne", "vulnerability disclosure" |
Quick Decision Tree
What do you want to do?
- Set up managed policies -> Query docs-management: "enterprise managed policy", "managed-settings.json"
- Understand precedence -> Query docs-management: "settings precedence", "enterprise policies precedence"
- Find policy file locations -> Query docs-management: "enterprise policy paths", "policy file locations"
- Configure cloud security -> Query docs-management: "cloud execution security", "isolated virtual machines"
- Understand IDE security -> Query docs-management: "VS Code security", "JetBrains security"
- Set up devcontainer -> Query docs-management: "devcontainer security", "container isolation"
- Follow best practices -> Query docs-management: "team security", "security best practices"
Topic Coverage
Managed Policies Topics
- managed-settings.json locations (macOS, Linux, Windows)
- Settings precedence hierarchy
- Unoverridable organizational policies
- Policy enforcement mechanisms
Cloud Security Topics
- Isolated virtual machines
- Network access controls
- Credential protection
- Branch restrictions
- Audit logging
- Automatic cleanup
IDE Security Topics
- VS Code extension security
- JetBrains plugin security
- IDE-specific security contexts
DevContainer Topics
- Container isolation benefits
- Security features in devcontainer setup
- Integration with sandboxing
Best Practices Topics
- Working with sensitive code
- Team security standards
- Reporting security issues (HackerOne)
- Vulnerability disclosure
Troubleshooting Quick Reference
| Issue |
Keywords for docs-management |
| Policy not applied |
"enterprise managed policy", "settings precedence" |
| Wrong precedence |
"settings precedence", "enterprise policies precedence" |
| Cloud security issues |
"cloud execution security", "network access controls" |
| IDE security concerns |
"VS Code security", "JetBrains security" |
| Container issues |
"devcontainer security", "container isolation" |
Related Skills
- sandbox-configuration - For sandboxing and isolation
- permission-management - For allow/deny/ask rules
- settings-management - For general configuration
Version History
- v1.0.0 (2025-11-30): Initial release (split from security-meta)
- Focused on enterprise security only
- Pure delegation architecture
- Comprehensive keyword registry
Last Updated
Date: 2025-11-30
Model: claude-opus-4-5-20251101
1---2name: enterprise-security3description: Central authority for Claude Code enterprise security. Covers enterprise managed policies (managed-settings.json), settings precedence hierarchy, policy file locations (macOS, Linux, Windows), unoverridable organizational policies, cloud execution security (isolated VMs, network access controls, credential protection), IDE security (VS Code, JetBrains), devcontainer security, and security best practices for teams. Assists with configuring enterprise policies, understanding precedence, and implementing organizational security standards. Delegates 100% to docs-management skill for official documentation.4---5
6# Enterprise Security Skill
7
8## MANDATORY: Invoke docs-management First
9
10> **STOP - Before providing ANY response about Claude Code enterprise security:**
11>
12> 1. **INVOKE** `docs-management` skill
13> 2. **QUERY** for the user's specific topic
14> 3. **BASE** all responses EXCLUSIVELY on official documentation loaded
15>
16> **Skipping this step results in outdated or incorrect information.**
17
18### Verification Checkpoint
19
20Before responding, verify:
21
22- [ ] Did I invoke docs-management skill?
23- [ ] Did official documentation load?
24- [ ] Is my response based EXCLUSIVELY on official docs?
25
26If ANY checkbox is unchecked, STOP and invoke docs-management first.
27
28---
29
30## Overview
31
32Central authority for Claude Code enterprise security. This skill uses **100% delegation to docs-management** - it contains NO duplicated official documentation.
33
34**Architecture:** Pure delegation with keyword registry. All official documentation is accessed via docs-management skill queries.
35
36## When to Use This Skill
37
38**Keywords:** enterprise, managed-settings.json, enterprise managed policy, settings precedence, organizational policies, cloud execution security, IDE security, VS Code security, JetBrains security, devcontainer security, team security, audit logging, credential protection
39
40**Use this skill when:**
41
42- Configuring enterprise managed policies
43- Understanding settings precedence
44- Setting up organizational security standards
45- Configuring cloud execution security
46- Understanding IDE security considerations
47- Setting up devcontainer security
48- Implementing team security practices
49
50## Keyword Registry for docs-management Queries
51
52Use these keywords when querying docs-management skill for official documentation:
53
54### Enterprise Managed Policies
55
56| Topic | Keywords |
57| --- | --- |
58| Overview | "enterprise managed policy", "managed-settings.json" |
59| File Locations | "enterprise policy paths", "policy file locations" |
60| Precedence | "settings precedence", "enterprise policies precedence" |
61| Unoverridable | "unoverridable policies", "organizational restrictions" |
62
63### Cloud Execution Security
64
65| Topic | Keywords |
66| --- | --- |
67| Overview | "cloud execution security", "isolated virtual machines" |
68| Network Controls | "network access controls", "cloud network security" |
69| Credentials | "credential protection", "cloud credential security" |
70| Branch Restrictions | "branch restrictions", "protected branches" |
71| Audit Logging | "audit logging", "security audit" |
72| Cleanup | "automatic cleanup", "cloud session cleanup" |
73
74### IDE Security
75
76| Topic | Keywords |
77| --- | --- |
78| VS Code | "VS Code security", "IDE security VS Code" |
79| JetBrains | "JetBrains security", "IDE security JetBrains" |
80| IDE Context | "IDE-specific security", "extension security" |
81
82### DevContainer Security
83
84| Topic | Keywords |
85| --- | --- |
86| Container Isolation | "devcontainer security", "container isolation" |
87| Security Features | "devcontainer security features", "container security" |
88| Integration | "devcontainer sandboxing", "container integration" |
89
90### Security Best Practices
91
92| Topic | Keywords |
93| --- | --- |
94| Team Security | "team security", "organizational standards" |
95| Sensitive Code | "working with sensitive code", "security best practices" |
96| Reporting Issues | "reporting security issues", "HackerOne", "vulnerability disclosure" |
97
98## Quick Decision Tree
99
100**What do you want to do?**
101
1021. **Set up managed policies** -> Query docs-management: "enterprise managed policy", "managed-settings.json"
1032. **Understand precedence** -> Query docs-management: "settings precedence", "enterprise policies precedence"
1043. **Find policy file locations** -> Query docs-management: "enterprise policy paths", "policy file locations"
1054. **Configure cloud security** -> Query docs-management: "cloud execution security", "isolated virtual machines"
1065. **Understand IDE security** -> Query docs-management: "VS Code security", "JetBrains security"
1076. **Set up devcontainer** -> Query docs-management: "devcontainer security", "container isolation"
1087. **Follow best practices** -> Query docs-management: "team security", "security best practices"
109
110## Topic Coverage
111
112### Managed Policies Topics
113
114- managed-settings.json locations (macOS, Linux, Windows)
115- Settings precedence hierarchy
116- Unoverridable organizational policies
117- Policy enforcement mechanisms
118
119### Cloud Security Topics
120
121- Isolated virtual machines
122- Network access controls
123- Credential protection
124- Branch restrictions
125- Audit logging
126- Automatic cleanup
127
128### IDE Security Topics
129
130- VS Code extension security
131- JetBrains plugin security
132- IDE-specific security contexts
133
134### DevContainer Topics
135
136- Container isolation benefits
137- Security features in devcontainer setup
138- Integration with sandboxing
139
140### Best Practices Topics
141
142- Working with sensitive code
143- Team security standards
144- Reporting security issues (HackerOne)
145- Vulnerability disclosure
146
147## Troubleshooting Quick Reference
148
149| Issue | Keywords for docs-management |
150| --- | --- |
151| Policy not applied | "enterprise managed policy", "settings precedence" |
152| Wrong precedence | "settings precedence", "enterprise policies precedence" |
153| Cloud security issues | "cloud execution security", "network access controls" |
154| IDE security concerns | "VS Code security", "JetBrains security" |
155| Container issues | "devcontainer security", "container isolation" |
156
157## Related Skills
158
159- **sandbox-configuration** - For sandboxing and isolation
160- **permission-management** - For allow/deny/ask rules
161- **settings-management** - For general configuration
162
163## Version History
164
165- **v1.0.0** (2025-11-30): Initial release (split from security-meta)
166 - Focused on enterprise security only
167 - Pure delegation architecture
168 - Comprehensive keyword registry
169
170---
171
172## Last Updated
173
174**Date:** 2025-11-30
175**Model:** claude-opus-4-5-20251101