Analyze git repositories to build a security ownership topology (people-to-file), compute bus factor and sensitive-code ownership, and export CSV/JSON for graph databases and visualization. Trigger only when the user explicitly wants a security-oriented ownership or bus-factor analysis grounded in git history (for example: orphaned sensitive code, security maintainers, CODEOWNERS reality checks for risk, sensitive hotspots, or ownership clusters). Do not trigger for general maintainer lists or non-security ownership questions.
Analyze git repositories to build a security ownership topology (people-to-file), compute bus factor and sensitive-code ownership, and export CSV/JSON for graph databases and visualization. Trigger only when the user explicitly wants a security-oriented ownership or bus-factor analysis grounded in git history (for example: orphaned sensitive code, security maintainers, CODEOWNERS reality checks for risk, sensitive hotspots, or ownership clusters). Do not trigger for general maintainer lists or non-security ownership questions.
Default operating pattern
Identify assets, trust boundaries, attacker assumptions, and sensitive flows.
Inspect the current implementation or design surface that creates risk.
Rank issues by impact, likelihood, and exploitability.
Recommend the smallest safe-by-default changes that materially reduce exposure.
Note verification steps and any residual risk that still remains.
Pack fit
Included in: security-quality
Keep examples generic, privacy-safe, and portable across hosts.
Boundary
Do not use for generic maintainer lists that do not involve security ownership.
1---2name: security-ownership-map3description: Analyze git repositories to build a security ownership topology (people-to-file), compute bus factor and sensitive-code ownership, and export CSV/JSON for graph databases and visualization. Trigger only when the user explicitly wants a security-oriented ownership or bus-factor analysis grounded in git history (for example: orphaned sensitive code, security maintainers, CODEOWNERS reality checks for risk, sensitive hotspots, or ownership clusters). Do not trigger for general maintainer lists or non-security ownership questions.4---56# security-ownership-map78## Intent9- Analyze git repositories to build a security ownership topology (people-to-file), compute bus factor and sensitive-code ownership, and export CSV/JSON for graph databases and visualization. Trigger only when the user explicitly wants a security-oriented ownership or bus-factor analysis grounded in git history (for example: orphaned sensitive code, security maintainers, CODEOWNERS reality checks for risk, sensitive hotspots, or ownership clusters). Do not trigger for general maintainer lists or non-security ownership questions.1011## Default operating pattern121. Identify assets, trust boundaries, attacker assumptions, and sensitive flows.132. Inspect the current implementation or design surface that creates risk.143. Rank issues by impact, likelihood, and exploitability.154. Recommend the smallest safe-by-default changes that materially reduce exposure.165. Note verification steps and any residual risk that still remains.1718## Pack fit19- Included in: `security-quality`20- Keep examples generic, privacy-safe, and portable across hosts.2122## Boundary23- Do not use for generic maintainer lists that do not involve security ownership.
Run npx skillmds@latest add hebertzhu/security-ownership-map in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.
Analyze git repositories to build a security ownership topology (people-to-file), compute bus factor and sensitive-code ownership, and export CSV/JSON for graph databases and visualization. Trigger only when the user explicitly wants a security-oriented ownership or bus-factor analysis grounded in git history (for example: orphaned sensitive code, security maintainers, CODEOWNERS reality checks for risk, sensitive hotspots, or ownership clusters). Do not trigger for general maintainer lists or non-security ownership questions. It is listed under Data & Analytics on SkillMD.
This skill has not completed SkillMD's automated safety review yet. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.
This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.
Yes. Installing skills from SkillMD is free, and the skill stays under its author's original license.
hebertzhu (@hebertzhu) published this skill. Their other Agent Skills are listed on their SkillMD profile.