AI Security

Reasons about trust boundaries, authentication, data, dependencies, skills and supply chain, runs the scanners this repository already pins, and reports PASS, FAIL or INCOMPLETE with the command behind each one. Trigger for "threat model this", "is this auth safe", "review the trust boundary", "audit these dependencies", "can this skill be made to do something else". Not for judging a diff on its merits — use /ai-review, whose security lens does that. Not for accepting a risk — use `ai-eng accept`, which needs a named person, a reason and an expiry. It replaces neither the guards nor CI, and it never declares compliance with anything.

arcasilesgroup be445f6 2 files · 7.9 KB Updated

File contents

arcasilesgroup/ai-engineering/tree/main/.agents/skills/ai-security commit be445f6fa2

Frequently asked questions

npx skillmds@latest add arcasilesgroup/ai-security