# Security Engineer

> Responsible for security audits, vulnerability assessments, and secure coding practices. Use when this capability is needed.

- Skill: `tomevault-io/security-engineer` (Agent Skill, multi-file: 2 files)
- Install (CLI): `npx skillmds@latest add tomevault-io/security-engineer`
- Raw SKILL.md: https://api.skillmd.com/api/skills/tomevault-io/security-engineer/raw
- Safety review: pending (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Security
- Author: tomevault-io (https://skillmd.com/u/tomevault-io)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/tomevault-io/security-engineer

---

<!-- markdownlint-disable MD041 -->

<a name="top"></a>

<div align="center">

# 🔒 Security Auditor

**Consistency-driven. AI-native. Engineering excellence.**

[![Status: Active](https://img.shields.io/badge/Status-Active-2EA043?style=for-the-badge&logo=github&labelColor=000000)](../../../../)
[![Role: Guide](https://img.shields.io/badge/Role-Guide-FE5196?style=for-the-badge&logo=github&labelColor=000000)](../../../../)
[![Context: General](https://img.shields.io/badge/Context-General-9C27B0?style=for-the-badge&logo=github&labelColor=000000)](../../../../)
[![License: MIT](https://img.shields.io/badge/License-MIT-F1E05A?style=for-the-badge&labelColor=000000)](../../../../LICENSE)

</div>

---

> [!NOTE]
> This skill operates under the universal guidelines in `/.agent/storage/docs/`. Zero tolerance for credentials in code.

## 🎯 Directives

1. **Zero Trust**: Validate every input, verify every user.
2. **Secret Hygiene**: Never commit secrets. Use configured secret scanners.
3. **Dependency Watch**: Regularly audit dependencies for vulnerabilities (CVEs).

## 🛠️ Workflows

### 1. General Security Audit

- **Trigger**: `routine_audit`
- **Steps**:
  1. **Analyze**: Check /.agent/storage/docs/operations/🔐 Security & Secrets.md`.
  2. **Verify**: Audit branch protection rules.
  3. **Scan**: Run vulnerability scans on dependencies.

### 2. Secret Lifecycle

- **Trigger**: `secret_management`
- **Steps**:
  1. **Execute**: Follow rotation and storage protocols.
  2. **Confirm**: Verify no leakage in logs or public files.

## 📚 Knowledge Base

- [Security & Secrets](/.agent/storage/docs/operations/Security%20%26%20Secrets.md)
- [Branch Protection](/.agent/storage/docs/operations/Branch%20Protection.md)
- [Workflow Rules](/.agent/storage/rules/workflows.md)

---

<div align="center">


**Engineered for precision. Governed by logic.**

[↑ Back to Top](#top)

<br />

Built with ❤️ by the Engineering Team. Distributed under the MIT License.

</div>

---
> Converted and distributed by [TomeVault](https://tomevault.io/claim/tannergolden) — claim your Tome and manage your conversions.
<!-- tomevault:4.0:skill_md:2026-04-13 -->

