Security Compliance
sangrokjung/claude-forge
Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and…
Design comprehensive security architectures using defense-in-depth, zero trust principles, threat modeling (STRIDE, PASTA), and control frameworks (NIST CSF, CIS Controls, ISO 27001).
$ npx skills add ancoleman/ai-design-components --skill architecting-security -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ancoleman/ai-design-components architecting-security --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ancoleman/ai-design-components.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/architecting-security .claude/skills/architecting-security && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "architecting-security" agent skill from https://github.com/ancoleman/ai-design-components/tree/main/skills/architecting-security into .claude/skills/architecting-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "architecting-security", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ancoleman/ai-design-components/tree/main/skills/architecting-securityType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ancoleman/ai-design-components --skill architecting-security -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ancoleman/ai-design-components architecting-security --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ancoleman/ai-design-components.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/architecting-security .agents/skills/architecting-security && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "architecting-security" agent skill from https://github.com/ancoleman/ai-design-components/tree/main/skills/architecting-security into .agents/skills/architecting-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "architecting-security", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ancoleman/ai-design-components --skill architecting-security -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ancoleman/ai-design-components architecting-security --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ancoleman/ai-design-components.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/architecting-security .cursor/skills/architecting-security && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "architecting-security" agent skill from https://github.com/ancoleman/ai-design-components/tree/main/skills/architecting-security into .cursor/skills/architecting-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "architecting-security", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ancoleman/ai-design-components.git --path skills/architecting-security--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ancoleman/ai-design-components --skill architecting-security -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ancoleman/ai-design-components architecting-security --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ancoleman/ai-design-components.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/architecting-security .gemini/skills/architecting-security && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "architecting-security" agent skill from https://github.com/ancoleman/ai-design-components/tree/main/skills/architecting-security into .gemini/skills/architecting-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "architecting-security", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ancoleman/ai-design-components architecting-securityInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ancoleman/ai-design-components --skill architecting-security -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ancoleman/ai-design-components.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/architecting-security .github/skills/architecting-security && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "architecting-security" agent skill from https://github.com/ancoleman/ai-design-components/tree/main/skills/architecting-security into .github/skills/architecting-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "architecting-security", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ancoleman/ai-design-components --skill architecting-security -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ancoleman/ai-design-components architecting-security --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ancoleman/ai-design-components.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/architecting-security .opencode/skills/architecting-security && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "architecting-security" agent skill from https://github.com/ancoleman/ai-design-components/tree/main/skills/architecting-security into .opencode/skills/architecting-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "architecting-security", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
architecting-securityDesign comprehensive security architectures using defense-in-depth, zero trust principles, threat modeling (STRIDE, PASTA), and control frameworks (NIST CSF, CIS Controls, ISO 27001).
Architecting Security is an agent skill from ancoleman/ai-design-components. Design comprehensive security architectures using defense-in-depth, zero trust principles, threat modeling (STRIDE, PASTA), and control frameworks (NIST CSF, CIS Controls, ISO 27001). Use when designing security for new systems, auditing existing architectures, or establishing security governance programs.
Its SKILL.md is about 6.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 26 other files, including scripts and reference files (for example `examples/architectures/aws-multi-account-security.md`, `examples/architectures/azure-landing-zone.md` and `examples/architectures/gcp-security-hierarchy.md`).
It sits in Security, covering Threat modeling, Secure coding and SOC 2 and security compliance. The repository describes itself as: Comprehensive UI/UX and Backend component design skills for AI-assisted development with Claude. The licence is MIT.
3 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 76551b7. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/, which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Architecting Security loads about 6.3k tokens when it runs, and up to ~36k if it reads all its reference files. Until then it costs about 82 tokens; SKILL.md has 2,736 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from ancoleman/ai-design-components at commit 76551b7, republished under its MIT licence (© ancoleman). 2,736 words, ~6,329 tokens.
.claude/skills/architecting-security/SKILL.md (or your agent's skills folder). This skill also uses 22 other files; get the full folder from GitHub.Design and implement comprehensive security architectures that protect systems, data, and users through layered defense strategies, zero trust principles, and risk-based security controls.
Security architecture provides the strategic foundation for building resilient, compliant, and trustworthy systems. This skill guides the design of defense-in-depth layers, zero trust implementations, threat modeling methodologies, and mapping to control frameworks (NIST CSF, CIS Controls, ISO 27001).
Unlike tactical security skills (configuring firewalls, implementing authentication, scanning vulnerabilities), security architecture focuses on strategic planning, comprehensive defense strategies, and governance frameworks.
Use security architecture when:
Implement multiple independent layers of security controls so that if one layer fails, others continue to protect critical assets.
9 Defense Layers (2025 Model):
Key Principle: Each layer provides independent protection. Failure of one layer does not compromise the entire system.
For detailed layer-by-layer implementation patterns, see references/defense-in-depth.md.
Implement "never trust, always verify" principles where every access request is authenticated, authorized, and continuously validated.
Core Zero Trust Principles:
Zero Trust Architecture Components:
For zero trust implementation roadmap and reference architecture, see references/zero-trust-architecture.md.
Systematically identify, prioritize, and mitigate security threats through structured methodologies.
Primary Methodologies:
| Methodology | Purpose | Complexity | Best For |
|---|---|---|---|
| STRIDE | Threat identification | Low | Development teams, quick threat analysis |
| PASTA | Risk-centric analysis | High | Enterprise risk management |
| DREAD | Risk scoring | Low | Prioritizing existing threats |
| Attack Trees | Visual threat analysis | Medium | Security architecture reviews |
STRIDE Threat Categories:
STRIDE Application Process:
For detailed threat modeling methodologies, PASTA process, DREAD scoring, and attack trees, see references/threat-modeling.md. For threat modeling examples, see examples/threat-models/.
Map security controls to industry frameworks to ensure comprehensive coverage and compliance.
6 Core Functions:
Usage: Map security controls to NIST CSF categories to ensure coverage of all security functions. Provides risk-based, flexible framework for security programs.
For detailed NIST CSF category mapping and subcategories, see references/nist-csf-mapping.md.
18 Controls organized in 3 Implementation Groups:
Top Priority Controls (IG1):
Usage: CIS Controls provide prescriptive, measurable security baseline. Start with IG1, progress to IG2/IG3 as security maturity increases.
For detailed CIS Controls implementation guidance, see references/cis-controls.md.
Map OWASP Top 10 application security risks to architectural controls:
| OWASP Risk | Primary Control | Framework Mapping |
|---|---|---|
| Injection | Parameterized queries, input validation | NIST PR.DS, CIS 16 |
| Broken Authentication | MFA, secure session management | NIST PR.AC, CIS 5, 6 |
| Sensitive Data Exposure | Encryption, key management | NIST PR.DS, CIS 3 |
| XXE | Disable external entities, use JSON | NIST PR.DS, CIS 16 |
| Broken Access Control | Authorization checks, RBAC | NIST PR.AC, CIS 6 |
| Security Misconfiguration | Hardening, minimal configs | NIST PR.IP, CIS 4 |
| XSS | Output encoding, CSP | NIST PR.DS, CIS 16 |
| Insecure Deserialization | Validate objects, safe formats | NIST PR.DS, CIS 16 |
| Known Vulnerabilities | Patch management, SBOM | NIST ID.RA, CIS 7 |
| Logging & Monitoring | SIEM, centralized logging | NIST DE.CM, CIS 8 |
For detailed OWASP Top 10 mitigation strategies and code examples, see references/owasp-top10-mitigation.md.
Select appropriate security architecture approach based on system characteristics:
Greenfield (New System):
Brownfield (Existing System):
Compliance-Driven:
Cloud-Native:
Hybrid/Multi-Cloud:
For detailed architecture selection decision trees, see references/defense-in-depth.md and references/zero-trust-architecture.md.
Protect software supply chain from tampering, backdoors, and compromised dependencies.
Supply-chain Levels for Software Artifacts (4 levels):
Implementation: Start with Level 1 provenance generation, progress to Level 2 (GitHub Actions), then Level 3 (hardened CI/CD with audit logs).
Generate and maintain inventory of software components and dependencies.
SBOM Standards:
SBOM Use Cases:
Dependency Management Best Practices:
For SLSA implementation guide, SBOM generation examples, and dependency scanning automation, see references/supply-chain-security.md.
Well-Architected Framework - Security Pillar Principles:
Key AWS Security Services:
Multi-Account Strategy: Use AWS Organizations with Security OU (Security Account, Logging Account, Audit Account) and Workload OUs (Production, Non-Production). Apply Service Control Policies (SCPs) for guardrails.
For AWS reference architectures and multi-account security setup, see references/aws-security-architecture.md and examples/architectures/aws-multi-account-security.md.
Key GCP Security Services:
Organization Hierarchy: Structure with Organization → Folders (Production, Non-Production, Security) → Projects. Apply IAM policies at folder level for inheritance.
For GCP security architecture patterns and organization setup, see references/gcp-security-architecture.md and examples/architectures/gcp-security-hierarchy.md.
Key Azure Security Services:
Hub-Spoke Landing Zone: Implement hub VNet (shared services: firewall, VPN, Azure Bastion) with spoke VNets (workloads). Use Management Groups for policy hierarchy.
For Azure security architecture and hub-spoke design, see references/azure-security-architecture.md and examples/architectures/azure-landing-zone.md.
Multi-Factor Authentication (MFA):
Single Sign-On (SSO):
Role-Based Access Control (RBAC):
Attribute-Based Access Control (ABAC):
Policy-Based Access Control (PBAC):
Just-in-Time (JIT) Access:
Credential Vaulting:
For detailed IAM implementation patterns, MFA configuration, and PAM setup, see references/iam-patterns.md.
Centralize log aggregation, correlation, and alerting for security events.
Leading SIEM Platforms:
SIEM Architecture:
Automate incident response workflows to reduce mean time to respond (MTTR).
SOAR Capabilities:
Leading SOAR Platforms:
UEBA (User & Entity Behavior Analytics):
Threat Intelligence:
For SIEM architecture, SOAR playbook examples, and detection strategies, see references/security-operations.md.
Use this table to map risks to appropriate control frameworks:
| Risk/Requirement | Framework | Key Controls |
|---|---|---|
| General security program | NIST CSF 2.0 | All 6 functions (GV, ID, PR, DE, RS, RC) |
| Compliance baseline | CIS Controls v8 | IG1: Controls 1-18 (56 safeguards) |
| ISO certification | ISO 27001/27002 | 114 controls across 14 domains |
| Application security | OWASP ASVS | 286 security requirements (3 levels) |
| Cloud security (AWS) | AWS Well-Architected | Security Pillar: 10 design principles |
| Cloud security (GCP) | GCP Security Best Practices | Security Command Center architecture |
| Cloud security (Azure) | Azure Security Benchmark | Defender for Cloud controls |
| Supply chain security | SLSA + SBOM | Level 2+ SLSA, CycloneDX SBOM |
| Zero trust architecture | NIST SP 800-207 | ZTA tenets, deployment models |
| Privacy/GDPR | NIST Privacy Framework | Privacy engineering objectives |
Security architecture provides the strategic foundation for tactical security implementations:
infrastructure-as-code: Implement security architecture as code (secure defaults, hardening)kubernetes-operations: Apply K8s security architecture (RBAC, Pod Security, Network Policies)secret-management: Architect secrets management (KMS, Vault, rotation strategies)building-ci-pipelines: Secure CI/CD architecture (SAST/DAST integration, artifact signing)configuring-firewalls: Implement network perimeter layer of defense-in-depthvulnerability-management: Integrate vulnerability scanning into security architectureauth-security: Implement IAM layer details (MFA, RBAC/ABAC, session management)siem-logging: Implement security monitoring architecture (SIEM, log aggregation)compliance-frameworks: Map security architecture to compliance requirementsReplace VPN with identity-based access to applications.
Architecture:
Benefits: Eliminates lateral movement, reduces attack surface, improves user experience
Layer multiple security controls for web application protection.
Layers:
Continuously monitor and enforce security configurations across cloud environments.
Architecture:
Leading CSPM Tools: Wiz, Orca Security, Prisma Cloud, Microsoft Defender for Cloud
Defense in Depth:
references/defense-in-depth.md - 9-layer defense model, implementation patterns, failure impact analysisZero Trust Architecture:
references/zero-trust-architecture.md - ZTA principles, reference architecture, implementation roadmapThreat Modeling:
references/threat-modeling.md - STRIDE, PASTA, DREAD, Attack Trees methodologiesexamples/threat-models/web-app-stride.md - Web application STRIDE analysis exampleexamples/threat-models/api-threat-model.md - REST API threat model exampleexamples/threat-models/microservices-threat-model.md - Microservices threat model exampleControl Frameworks:
references/nist-csf-mapping.md - NIST CSF 2.0 functions, categories, subcategoriesreferences/cis-controls.md - CIS Controls v8, implementation groups, safeguardsreferences/owasp-top10-mitigation.md - OWASP Top 10 risks and mitigation strategiesSupply Chain Security:
references/supply-chain-security.md - SLSA framework, SBOM generation, dependency scanningCloud Security:
references/aws-security-architecture.md - AWS Well-Architected Security Pillar, services, patternsreferences/gcp-security-architecture.md - GCP Security Best Practices, services, organization designreferences/azure-security-architecture.md - Azure Security Benchmark, Defender for Cloud, landing zonesIAM & Operations:
references/iam-patterns.md - Authentication, authorization, MFA, RBAC/ABAC, PAMreferences/security-operations.md - SIEM, SOAR, UEBA, threat intelligence, incident responseArchitecture Examples:
examples/architectures/aws-multi-account-security.md - AWS Organizations security setupexamples/architectures/gcp-security-hierarchy.md - GCP folder/project security hierarchyexamples/architectures/azure-landing-zone.md - Azure hub-spoke landing zoneexamples/architectures/zero-trust-network.md - Zero trust network designScripts:
scripts/threat-model-template.py - Generate STRIDE threat model templatesscripts/control-gap-analysis.sh - Compare current controls against frameworksscripts/sbom-generate.sh - Generate SBOM in CycloneDX formatscripts/security-checklist.sh - Automated security architecture checklistSecurity architecture requires strategic planning across multiple layers, from physical security to security operations. Implement defense-in-depth for comprehensive protection, adopt zero trust principles for modern cloud environments, use threat modeling to identify risks proactively, and map controls to frameworks for compliance and completeness.
Start with risk assessment to understand threats, select appropriate architecture approach (zero trust for greenfield, hybrid for brownfield), implement layered controls, and continuously monitor and improve security posture.
© ancoleman, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 22 other files (scripts, references) in skills/architecting-security of ancoleman/ai-design-components.
Open the folder on GitHubat commit 76551b7
Architecting Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Architecting Security this skillancoleman/ai-design-components | 526 | — | ~6.3k | Automated safety check: Pass | MIT | |
| Security Compliancesangrokjung/claude-forge | 850 | 2 repos | ~7.2k | Automated safety check: Pass | MIT | |
| Senior Securityborghei/Claude-Skills | 881 | — | ~1.8k | Automated safety check: Pass | MIT | |
| Security By DesignHack23/cia | 239 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | |
| Goericrisco/rsc-harness | 167 | — | ~3.9k | Automated safety check: Pass | MIT | |
| Security And Hardeningpenpot/penpot | 61k | 6 repos | ~4.7k | Automated safety check: Notes | MPL-2.0 |
sangrokjung/claude-forge
Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and…
borghei/Claude-Skills
STRIDE threat modeling, DREAD risk scoring, secret detection, and secure architecture design.
Hack23/cia
Threat modeling before coding, STRIDE methodology, defense in depth, security controls in SDLC
ericrisco/rsc-harness
A skill your agent uses when writing, reviewing, testing, or shipping Go code and HTTP services: idioms, %w error wrapping, goroutine/context/errgroup concurrency, net/http 1.22 routing, log/slog…
penpot/penpot
Hardens code against vulnerabilities. An agent skill from penpot/penpot.
ruvnet/ruflo
Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.
ancoleman/ai-design-components
Builds AI chat interfaces and conversational UI with streaming responses, context management, and multi-modal support.
ancoleman/ai-design-components
Builds form components and data collection interfaces including contact forms, registration flows, checkout processes, surveys, and settings pages.
ancoleman/ai-design-components
Builds tables and data grids for displaying tabular information, from simple HTML tables to complex enterprise data grids.
ancoleman/ai-design-components
Creates comprehensive dashboard and analytics interfaces that combine data visualization, KPI cards, real-time updates, and interactive layouts.
ancoleman/ai-design-components
Designs layout systems and responsive interfaces including grid systems, flexbox patterns, sidebar layouts, and responsive breakpoints.
ancoleman/ai-design-components
Displays chronological events and activity through timelines, activity feeds, Gantt charts, and calendar interfaces.
Categories
Design comprehensive security architectures using defense-in-depth, zero trust principles, threat modeling (STRIDE, PASTA), and control frameworks (NIST CSF, CIS Controls, ISO 27001). Architecting Security is an agent skill from ancoleman/ai-design-components. Design comprehensive security architectures using defense-in-depth, zero trust principles, threat modeling (STRIDE, PASTA), and control frameworks (NIST CSF, CIS Controls, ISO 27001).
Architecting Security fits situations like: designing security for new systems; auditing existing architectures; establishing security governance programs.
Run `npx skills add ancoleman/ai-design-components --skill architecting-security -a claude-code`. Or copy the skill folder (skills/architecting-security in ancoleman/ai-design-components) into .claude/skills/architecting-security in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ancoleman/ai-design-components --skill architecting-security -a codex`. Or copy the skill folder (skills/architecting-security in ancoleman/ai-design-components) into .agents/skills/architecting-security in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ancoleman/ai-design-components --skill architecting-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/architecting-security, .gemini/skills/architecting-security, .github/skills/architecting-security and .opencode/skills/architecting-security in your project.
SKILL.md names no scripts, command-line tools or credentials: Architecting Security is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Architecting Security is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 6.3k tokens (SKILL.md is roughly 25k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 30k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Architecting Security: Security Compliance (sangrokjung/claude-forge, 850 stars), Senior Security (borghei/Claude-Skills, 881 stars), Security By Design (Hack23/cia, 239 stars) and Go (ericrisco/rsc-harness, 167 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ancoleman (a GitHub user) maintains it in ancoleman/ai-design-components, which has 526 GitHub stars. The repository holds 75 skills in this directory. The repository was last updated on December 11, 2025.
Source: ancoleman/ai-design-components on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.