Security review checklist for construction software systems.

MITAuto-check passedSecurity

Install Security Review Construction

skills CLI
$ npx skills add datadrivenconstruction/DDC_Skills_for_AI_Agents_in_Construction --skill security-review-construction -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install datadrivenconstruction/DDC_Skills_for_AI_Agents_in_Construction security-review-construction --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/datadrivenconstruction/DDC_Skills_for_AI_Agents_in_Construction.git skills-src && mkdir -p .claude/skills && cp -r skills-src/4_DDC_Curated/Quality-Assurance/security-review-construction .claude/skills/security-review-construction && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-review-construction
GitHub stars
345
Token cost
~3.3k tokens
SKILL.md length
431 words
Files
3
Skills in repo
36
Repo updated
First seen
Licence
MIT

At a glance

Security review checklist for construction software systems.

  • Works in 7 steps: Financial Data Protection → BIM/CAD Data Security → Subcontractor/Vendor Data → …
  • Building integrations
  • SKILL.md covers When to Activate, Construction-Specific Security…, Pre-Deployment Security… and Resources
  • Needs ENCRYPTION_KEY

What it does

Security Review Construction is an agent skill from datadrivenconstruction/DDC_Skills_for_AI_Agents_in_Construction. Security review checklist for construction software systems. Use when building integrations, APIs, data pipelines, or dashboards for construction projects.

Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `claw.json` and `instructions.md`).

It sits in Security, covering Security review and Data pipelines and ETL. The repository describes itself as: 221 AI skills for construction: BIM analysis, cost estimation, scheduling, document control, and automation with Claude Code. The licence is MIT.

When your agent uses it

  • Building integrations
  • Dashboards for construction projects

Example prompts

  • “/security-review-construction”

Requirements

  • Python 3
  • A credential in ENCRYPTION_KEY

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Financial Data Protection
  2. BIM/CAD Data Security
  3. Subcontractor/Vendor Data
  4. Field Data Collection Security
  5. CWICR Database Security
  6. Integration Security (Procore, PlanGrid, etc.)
  7. Document Management Security

What it can do on your machine

Read from SKILL.md and the folder at commit ce45bbf. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are python).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • owasp.org
    • nist.gov
    • cisecurity.org
    • iso.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • ENCRYPTION_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Review Construction loads about 3.3k tokens when it runs. Until then it costs about 46 tokens; SKILL.md has 431 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~46
When it runs · the whole SKILL.md, loaded when a task matches
~3.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from datadrivenconstruction/DDC_Skills_for_AI_Agents_in_Construction at commit ce45bbf, republished under its MIT licence (© datadrivenconstruction). 431 words, ~3,294 tokens.

Download SKILL.mdSave it as .claude/skills/security-review-construction/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
security-review-construction
description
Security review checklist for construction software systems. Use when building integrations, APIs, data pipelines, or dashboards for construction projects.
homepage
https://datadrivenconstruction.io

Security Review Skill for Construction Systems

This skill ensures all construction software systems follow security best practices, protecting sensitive project data, financial information, and business intelligence.

When to Activate

  • Building ERP/BIM system integrations
  • Creating construction dashboards
  • Handling cost/financial data
  • Building document management systems
  • Creating APIs for field data collection
  • Integrating with external platforms (Procore, PlanGrid, etc.)
  • Working with subcontractor/vendor data
  • Processing payment applications

Construction-Specific Security Concerns

1. Financial Data Protection
python
# CRITICAL: Construction financial data security

# ❌ NEVER Do This
project_budget = 15000000  # Hardcoded in source
margin_percentage = 0.18   # Business-sensitive info in code

# ✅ ALWAYS Do This
import os
from cryptography.fernet import Fernet

# Load from secure configuration
project_config = load_secure_config(os.environ['PROJECT_CONFIG_PATH'])

# Encrypt sensitive data at rest
def encrypt_financial_data(data: dict) -> bytes:
    key = os.environ.get('ENCRYPTION_KEY')
    f = Fernet(key)
    return f.encrypt(json.dumps(data).encode())
Financial Data Checklist
  • Cost estimates encrypted at rest
  • Margin/markup data not exposed in logs
  • Payment information tokenized
  • Historical pricing protected from competitors
  • Bid amounts secured until opening
2. BIM/CAD Data Security
python
# BIM data often contains proprietary design information

# ❌ NEVER store BIM directly in public cloud without encryption
s3.upload_file('model.ifc', bucket='public-bucket')

# ✅ ALWAYS encrypt and control access
def upload_bim_secure(file_path: str, project_id: str):
    # Encrypt file
    encrypted_path = encrypt_file(file_path)

    # Generate pre-signed URL with expiration
    presigned_url = s3.generate_presigned_url(
        'get_object',
        Params={
            'Bucket': 'secure-bim-bucket',
            'Key': f'{project_id}/{os.path.basename(file_path)}'
        },
        ExpiresIn=3600  # 1 hour expiration
    )

    # Log access
    audit_log.info(f"BIM access granted: {project_id}")

    return presigned_url
BIM/CAD Checklist
  • IFC/RVT files encrypted at rest
  • Access logged for audit trail
  • Time-limited download links
  • Version control with access tracking
  • No design data in error messages
3. Subcontractor/Vendor Data
python
# Subcontractor data includes business-sensitive information

class SubcontractorDataHandler:
    """Secure handling of subcontractor data"""

    # Fields that require encryption
    SENSITIVE_FIELDS = [
        'insurance_policy_number',
        'bank_account',
        'tax_id',
        'bonding_capacity',
        'historical_pricing'
    ]

    def store_subcontractor(self, data: dict) -> str:
        # Encrypt sensitive fields
        for field in self.SENSITIVE_FIELDS:
            if field in data:
                data[field] = self.encrypt(data[field])

        # Store with audit trail
        sub_id = self.db.insert(data)
        self.audit.log(f"Subcontractor created: {sub_id}")

        return sub_id

    def get_subcontractor(self, sub_id: str, requester_id: str) -> dict:
        # Check authorization
        if not self.can_access(requester_id, sub_id):
            raise PermissionError("Unauthorized access to subcontractor data")

        # Log access
        self.audit.log(f"Subcontractor accessed: {sub_id} by {requester_id}")

        # Return with decrypted sensitive fields (only to authorized users)
        return self.decrypt_sensitive_fields(self.db.get(sub_id))
Vendor Data Checklist
  • Insurance/bonding information encrypted
  • Bank details protected (PCI compliance)
  • Tax IDs masked in UI (show last 4 digits only)
  • Pricing history access-controlled
  • Certificate expiration notifications secure
4. Field Data Collection Security
python
# Mobile/field data collection must be secure

from datetime import datetime, timedelta
import hashlib

class FieldDataCollector:
    """Secure field data collection"""

    def validate_photo_submission(self, photo_data: dict) -> bool:
        # Verify GPS timestamp is recent (within 24 hours)
        photo_time = datetime.fromisoformat(photo_data['timestamp'])
        if datetime.now() - photo_time > timedelta(hours=24):
            raise ValueError("Photo timestamp too old - possible replay attack")

        # Verify file hash matches
        file_hash = hashlib.sha256(photo_data['content']).hexdigest()
        if file_hash != photo_data['declared_hash']:
            raise ValueError("File integrity check failed")

        # Validate GPS coordinates are within project boundary
        if not self.is_within_project_bounds(
            photo_data['lat'],
            photo_data['lon'],
            photo_data['project_id']
        ):
            self.audit.warn(f"Photo from outside project bounds: {photo_data}")

        return True

    def submit_daily_report(self, report: dict, user_id: str) -> str:
        # Verify user is assigned to project
        if not self.is_assigned_to_project(user_id, report['project_id']):
            raise PermissionError("User not assigned to this project")

        # Sign report with user credentials
        report['signature'] = self.sign_report(report, user_id)
        report['submitted_at'] = datetime.now().isoformat()

        return self.db.insert(report)
Field Data Checklist
  • GPS data validated for reasonableness
  • Photo timestamps verified
  • File integrity checks (hashing)
  • User authentication for submissions
  • Offline data sync secured
5. CWICR Database Security
python
# CWICR contains proprietary cost data

class CWICRAccessControl:
    """Access control for CWICR database"""

    TIERS = {
        'basic': ['public_rates', 'standard_descriptions'],
        'professional': ['regional_rates', 'productivity_factors'],
        'enterprise': ['custom_rates', 'historical_data', 'analytics']
    }

    def search(self, query: str, user_id: str) -> list:
        # Get user tier
        tier = self.get_user_tier(user_id)

        # Limit results based on tier
        allowed_fields = self.TIERS[tier]

        # Execute search with field restrictions
        results = self.vector_search(
            query=query,
            fields=allowed_fields,
            limit=self.get_tier_limit(tier)
        )

        # Log search for analytics
        self.audit.log(f"CWICR search: {user_id}, query='{query[:50]}...'")

        return results

    def export_data(self, user_id: str, format: str) -> bytes:
        # Enterprise only
        if self.get_user_tier(user_id) != 'enterprise':
            raise PermissionError("Export requires enterprise tier")

        # Watermark exported data
        data = self.get_exportable_data(user_id)
        watermarked = self.add_watermark(data, user_id)

        return watermarked
CWICR Checklist
  • Tiered access control implemented
  • API rate limiting per user/tier
  • Data exports watermarked
  • Bulk download restrictions
  • Competitor access monitoring
6. Integration Security (Procore, PlanGrid, etc.)
python
# Secure OAuth integration with construction platforms

class ConstructionPlatformIntegration:
    """Secure integration with external platforms"""

    def __init__(self, platform: str):
        self.platform = platform
        # Load credentials from secure vault
        self.credentials = self.vault.get(f'{platform}_oauth')

    def authenticate(self) -> str:
        # Use OAuth 2.0 with PKCE
        code_verifier = secrets.token_urlsafe(32)
        code_challenge = base64.urlsafe_b64encode(
            hashlib.sha256(code_verifier.encode()).digest()
        ).decode().rstrip('=')

        # Never store tokens in code or logs
        token = self.oauth_flow(code_verifier, code_challenge)

        # Store token securely
        self.secure_token_store.set(
            key=f'{self.platform}_token',
            value=token,
            ttl=token['expires_in']
        )

        return token

    def sync_data(self, project_id: str) -> dict:
        # Validate project access before sync
        if not self.has_project_access(project_id):
            raise PermissionError(f"No access to project {project_id}")

        # Rate limit syncs
        self.rate_limiter.check(f'sync_{self.platform}')

        # Sync with retry and error handling
        try:
            data = self.api_client.get_project_data(project_id)
            self.validate_incoming_data(data)
            return data
        except APIError as e:
            # Log error without sensitive details
            self.logger.error(f"Sync failed for {project_id}: {type(e).__name__}")
            raise
Integration Checklist
  • OAuth 2.0 with PKCE implemented
  • Tokens stored in secure vault (not env vars)
  • Token refresh automated
  • API rate limiting respected
  • Webhook signatures verified
  • Data validation on incoming data
7. Document Management Security
python
# Construction documents often contain confidential information

class SecureDocumentManager:
    """Secure document handling for construction"""

    # Document classification levels
    CLASSIFICATIONS = {
        'public': [],
        'internal': ['daily_reports', 'schedules'],
        'confidential': ['contracts', 'bids', 'financials'],
        'restricted': ['legal', 'hr', 'insurance']
    }

    def upload_document(self, file: bytes, metadata: dict, user_id: str) -> str:
        # Scan for malware
        if not self.malware_scan(file):
            raise SecurityError("Malware detected in uploaded file")

        # Classify document
        classification = self.classify_document(metadata)

        # Check user can upload to this classification
        if not self.can_upload(user_id, classification):
            raise PermissionError(f"Cannot upload {classification} documents")

        # Encrypt based on classification
        if classification in ['confidential', 'restricted']:
            file = self.encrypt(file)

        # Store with audit trail
        doc_id = self.storage.put(file, metadata)
        self.audit.log(f"Document uploaded: {doc_id} by {user_id}")

        return doc_id

    def download_document(self, doc_id: str, user_id: str) -> bytes:
        # Check access
        doc = self.storage.get_metadata(doc_id)
        if not self.can_access(user_id, doc['classification']):
            raise PermissionError("Access denied")

        # Log download
        self.audit.log(f"Document downloaded: {doc_id} by {user_id}")

        # Return decrypted content
        return self.decrypt(self.storage.get(doc_id))
Show full SKILL.md (181 more words)Show less
Document Checklist
  • Malware scanning on upload
  • Document classification system
  • Role-based access control
  • Download audit logging
  • Encryption for sensitive documents
  • Retention policies enforced

Pre-Deployment Security Checklist for Construction Systems

Data Protection
  • Financial data encrypted at rest and in transit
  • BIM/CAD files protected with access control
  • Subcontractor PII secured (GDPR/CCPA compliant)
  • CWICR data access tiered appropriately
  • Backup encryption enabled
Authentication & Authorization
  • Multi-factor authentication for admin users
  • Role-based access control implemented
  • Session management secure (timeout, single device)
  • API keys rotated regularly
  • OAuth integrations use PKCE
Audit & Compliance
  • All data access logged
  • Logs tamper-proof (append-only)
  • Retention policies documented
  • Data export capabilities for audits
  • Compliance reports automated
Integration Security
  • All external APIs authenticated
  • Webhook signatures verified
  • Data validation on all inputs
  • Rate limiting implemented
  • Error messages sanitized
Field Data Security
  • Mobile apps use certificate pinning
  • Offline data encrypted
  • GPS/timestamp validation
  • Photo integrity verification
  • Secure sync protocols

Resources


Remember: Construction data includes financial, legal, and competitive information. A breach can result in lost bids, legal liability, and reputational damage. Security is not optional.

© datadrivenconstruction, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files in 4_DDC_Curated/Quality-Assurance/security-review-construction of datadrivenconstruction/DDC_Skills_for_AI_Agents_in_Construction.

  • SKILL.md
  • claw.json
  • instructions.md

Open the folder on GitHubat commit ce45bbf

Compare with similar skills

Security Review Construction next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Review Construction compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Review Construction this skilldatadrivenconstruction/DDC_Skills_for_AI_Agents_in_Construction345—~3.3kAutomated safety check: PassMIT
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Kubernetes Network Security Auditkubeshark/kubeshark12k—~7.3kAutomated safety check: NotesApache-2.0
Native Dependency Updatemono/SkiaSharp5.6k—~4.1kAutomated safety check: PassMIT
Semgrep Security Scantrailofbits/skills7.4k—~3.7kAutomated safety check: NotesCC-BY-SA-4.0
Skillward AuditFangcun-AI/SkillWard143—~2.9kAutomated safety check: PassCustom licence

Similar skills

  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 10 days ago
    SecurityAuto-check passed
  • Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.

    12k GitHub stars~7.3k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.

    5.6k GitHub stars~4.1k tokensUpdated today
    SecurityAuto-check passed
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.4k GitHub stars~3.7k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Skillward Audit

    Fangcun-AI/SkillWard

    Security-audit a third-party skill bundle (folder with SKILL.md, or .zip / .tar.gz archive) before installing it, using the SkillWard cloud scanner.

    143 GitHub stars~2.9k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Security Audit

    TheDecipherist/claude-code-mastery

    Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

    550 GitHub stars~1.3k tokensUpdated 5 mo ago
    SecurityAuto-check: notes

More from datadrivenconstruction/DDC_Skills_for_AI_Agents_in_Construction

All 36 skills in this repo
  • AI Agent Orchestration

    datadrivenconstruction/DDC_Skills_for_AI_Agents_in_Construction

    Orchestrate multiple AI agents for construction workflows: estimator, scheduler, document, QA and safety agents coordinated by a supervisor agent, with human checkpoints.

    345 GitHub stars~679 tokensUpdated 1 mo ago
    Auto-check passed
  • Embodied Carbon Esg

    datadrivenconstruction/DDC_Skills_for_AI_Agents_in_Construction

    Estimate embodied carbon and produce ESG/climate reporting for construction: LCA per work item, material-based carbon factors, EU taxonomy and CSRD alignment.

    345 GitHub stars~664 tokensUpdated 1 mo ago
    Auto-check passed
  • Generative AI Design

    datadrivenconstruction/DDC_Skills_for_AI_Agents_in_Construction

    Generative design for construction: text-to-BIM concepts, option generation, and AI-assisted design iteration with cost and carbon feedback.

    345 GitHub stars~593 tokensUpdated 1 mo ago
    Auto-check passed
  • Material Passports Circular

    datadrivenconstruction/DDC_Skills_for_AI_Agents_in_Construction

    Material passports and circular construction: generate per-element material inventories from BOQ/BIM, mark reuse potential and recycled content, and prepare deconstruction data.

    345 GitHub stars~634 tokensUpdated 1 mo ago
    Auto-check passed
  • ML Model Retrainer

    datadrivenconstruction/DDC_Skills_for_AI_Agents_in_Construction

    Automated pipeline for retraining ML models with new construction data.

    345 GitHub stars~4.6k tokensUpdated 1 mo ago
    Auto-check passed
  • Oce Cost Browser

    datadrivenconstruction/DDC_Skills_for_AI_Agents_in_Construction

    Browse and search the OpenConstructionERP cost database: classification tree, SQL and semantic search, autocomplete, certainty badges, and the resource catalog.

    345 GitHub stars~637 tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Security Review Construction

What does Security Review Construction do?

Security review checklist for construction software systems. Security Review Construction is an agent skill from datadrivenconstruction/DDC_Skills_for_AI_Agents_in_Construction. Security review checklist for construction software systems.

When should I use Security Review Construction?

Security Review Construction fits situations like: building integrations; dashboards for construction projects.

How do I install Security Review Construction in Claude Code?

Run `npx skills add datadrivenconstruction/DDC_Skills_for_AI_Agents_in_Construction --skill security-review-construction -a claude-code`. Or copy the skill folder (4_DDC_Curated/Quality-Assurance/security-review-construction in datadrivenconstruction/DDC_Skills_for_AI_Agents_in_Construction) into .claude/skills/security-review-construction in your project. Claude Code loads it when a task matches its description.

How do I install Security Review Construction in Codex?

Run `npx skills add datadrivenconstruction/DDC_Skills_for_AI_Agents_in_Construction --skill security-review-construction -a codex`. Or copy the skill folder (4_DDC_Curated/Quality-Assurance/security-review-construction in datadrivenconstruction/DDC_Skills_for_AI_Agents_in_Construction) into .agents/skills/security-review-construction in your project. Codex loads it when a task matches its description.

Can I use Security Review Construction in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add datadrivenconstruction/DDC_Skills_for_AI_Agents_in_Construction --skill security-review-construction -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-review-construction, .gemini/skills/security-review-construction, .github/skills/security-review-construction and .opencode/skills/security-review-construction in your project.

What does Security Review Construction need to run?

Going by SKILL.md and its folder, Security Review Construction needs credentials named ENCRYPTION_KEY. Our summary lists: Python 3; A credential in ENCRYPTION_KEY.

Does Security Review Construction access the network?

SKILL.md names 4 domains. As links in the text: owasp.org, nist.gov, cisecurity.org and iso.org. This is read from the text; nothing was executed.

Is Security Review Construction safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security Review Construction use?

Security Review Construction is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Review Construction use?

About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Review Construction?

Skills that share tags, products or a category with Security Review Construction: Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Kubernetes Network Security Audit (kubeshark/kubeshark, 12k stars), Native Dependency Update (mono/SkiaSharp, 5.6k stars) and Semgrep Security Scan (trailofbits/skills, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Review Construction?

datadrivenconstruction (a GitHub user) maintains it in datadrivenconstruction/DDC_Skills_for_AI_Agents_in_Construction, which has 345 GitHub stars. The repository holds 36 skills in this directory. The repository was last updated on August 22, 2026.

Source: datadrivenconstruction/DDC_Skills_for_AI_Agents_in_Construction on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.