# Security Projections

> Project processkit security policy Artifacts into runtime policy files for Agent-IDS and Tetragon-style enforcement. Use when an agent-ids-rule or image-provenance-policy Artifact must become an executable security configuration.

- Skill: `projectious-work/security-projections` (Agent Skill, multi-file: 4 files)
- Install (CLI): `npx skillmds@latest add projectious-work/security-projections`
- Raw SKILL.md: https://api.skillmd.com/api/skills/projectious-work/security-projections/raw
- Safety review: PASS (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: AI & ML
- Author: projectious-work (https://skillmd.com/u/projectious-work)
- Updated: 2026-08-19
- Page: https://skillmd.com/skills/projectious-work/security-projections

---


# Security Projections

## Intro

Security projections keep the source of truth in processkit Artifacts
while emitting runtime policy files for enforcement systems. Agent-IDS
rules project to canonical JSON. Tetragon tracing policies project to
YAML shaped like Cilium Tetragon `TracingPolicy` resources.

## Overview

Projection tools read security policy Artifacts and write runtime policy
files with deterministic content and checksums. The emitted files are
deployment artifacts; processkit Artifacts remain the reviewed policy
source.

## Gotchas

- Do not hand-edit projected policy files as the source of truth. Update
  the source Artifact and project again.
- Do not project broad enforcement policies without a related decision or
  gate evidence explaining the rollout scope.
- Treat missing projection checksums as stale output and regenerate before
  release.

## Full reference

### MCP tools

- `project_agent_ids_rule`
- `project_tetragon_tracing_policy`

### Source entities

- `Artifact(spec.kind=agent-ids-rule)`
- `Artifact(spec.kind=image-provenance-policy)`

