Agent skill

Secure Development Lifecycle

by Hack23 in Hack23/cia

Secure SDLC phases, security requirements, secure coding practices, and security testing integration for the CIA platform

Apache-2.0Auto-check passedSecurity

Install Secure Development Lifecycle

skills CLI
$ npx skills add Hack23/cia --skill secure-development-lifecycle -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Hack23/cia secure-development-lifecycle --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/secure-development-lifecycle .claude/skills/secure-development-lifecycle && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
secure-development-lifecycle
GitHub stars
239
Token cost
~1.8k tokens
SKILL.md length
475 words
Files
1
Skills in repo
78
Repo updated
First seen
Licence
Apache-2.0

At a glance

Secure SDLC phases, security requirements, secure coding practices, and security testing integration for the CIA platform

  • Works in 6 steps: Security Requirements → Secure Design → Secure Coding → …
  • Tasks that involve Secure coding
  • SKILL.md covers Purpose, When to Use This Skill, SDLC Phases and Decision Framework, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Secure Development Lifecycle is an agent skill from Hack23/cia. Secure SDLC phases, security requirements, secure coding practices, and security testing integration for the CIA platform

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Secure coding. The repository describes itself as: Citizen Intelligence Agency. Open-source intelligence platform analyzing Swedish political activities using AI and data visualization. Tracks politicians, government… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Secure coding

Example prompts

  • “/secure-development-lifecycle”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Security Requirements
  2. Secure Design
  3. Secure Coding
  4. Security Testing
  5. Secure Deployment
  6. Post-Deployment

What it can do on your machine

Read from SKILL.md and the folder at commit 6a9797b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are java and yaml).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • owasp.org
    • csrc.nist.gov
    • github.com
    • iso.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Secure Development Lifecycle loads about 1.8k tokens when it runs. Until then it costs about 38 tokens; SKILL.md has 475 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~38
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Hack23/cia at commit 6a9797b, republished under its Apache-2.0 licence (© Hack23). 475 words, ~1,772 tokens.

Download SKILL.mdSave it as .claude/skills/secure-development-lifecycle/SKILL.md (or your agent's skills folder).
name
secure-development-lifecycle
description
Secure SDLC phases, security requirements, secure coding practices, and security testing integration for the CIA platform
license
Apache-2.0

Secure Development Lifecycle Skill

Purpose

This skill provides guidance for integrating security into every phase of the software development lifecycle (SDLC) for the Citizen Intelligence Agency platform. It ensures that security is not an afterthought but a fundamental design principle from requirements through deployment.

When to Use This Skill

Apply this skill when:

  • ✅ Starting a new feature or module
  • ✅ Defining requirements for new functionality
  • ✅ Designing architecture for new components
  • ✅ Writing code that handles sensitive political data
  • ✅ Planning test strategies for new features
  • ✅ Preparing releases and deployments
  • ✅ Conducting post-deployment security reviews

Do NOT use for:

  • ❌ Operational security monitoring (use incident-response skill)
  • ❌ Infrastructure-level security (use security-architecture-validation)
  • ❌ Pure code review without lifecycle context (use secure-code-review)

SDLC Phases

Phase 1: Security Requirements

Define security requirements alongside functional requirements:

Requirement CategoryCIA Platform ExampleISMS Control
AuthenticationSpring Security login, 2FA enforcementISO 27001 A.8.5
AuthorizationRole-based access to admin viewsISO 27001 A.8.3
Data ProtectionEncryption of user credentialsISO 27001 A.8.24
Input ValidationSanitize all Riksdag API data inputsISO 27001 A.8.28
Audit LoggingLog all admin actions and data accessISO 27001 A.8.15
PrivacyGDPR compliance for user dataGDPR Art. 25

Security Requirements Checklist:

□ Threat model updated for new feature
□ Data classification level assigned
□ Authentication requirements defined
□ Authorization matrix updated
□ Input validation rules specified
□ Audit logging requirements defined
□ Privacy impact assessment completed
□ Compliance requirements mapped
Phase 2: Secure Design

Apply secure design principles:

  1. Defense in Depth — Multiple security layers (Spring Security filters, service-layer validation, JPA parameterized queries)
  2. Least Privilege — Minimal permissions for each role
  3. Fail Secure — Deny by default on errors
  4. Separation of Duties — Distinct service/model/web layers
  5. Economy of Mechanism — Simple, auditable security controls

Design Review Checklist:

□ Architecture follows existing layered pattern
□ No direct database access from web layer
□ All external API calls go through service layer
□ Error handling does not leak sensitive information
□ Session management uses Spring Security defaults
□ CSRF protection enabled for state-changing operations
Phase 3: Secure Coding

Follow secure coding practices specific to the CIA stack:

Java/Spring Security Practices:

java
// DO: Use parameterized queries via JPA
@Query("SELECT p FROM Politician p WHERE p.name = :name")
List<Politician> findByName(@Param("name") String name);

// DON'T: Concatenate user input into queries
// String query = "SELECT * FROM politician WHERE name = '" + name + "'";

// DO: Validate input at controller level
@Valid @RequestBody PoliticianRequest request

// DO: Use constructor injection
@Service
public class PoliticianService {
    private final PoliticianRepository repository;

    public PoliticianService(PoliticianRepository repository) {
        this.repository = repository;
    }
}

Key Coding Rules:

  • Never log sensitive data (passwords, tokens, PII)
  • Use @Transactional(readOnly = true) for read-only operations
  • Validate all inputs from external APIs (Riksdag, World Bank)
  • Encode output in Vaadin components to prevent XSS
  • Use Spring Security's CSRF protection for all forms
Show full SKILL.md (168 more words)Show less
Phase 4: Security Testing

Integrate security testing at multiple levels:

Test LevelTool/ApproachWhenCoverage Target
Unit TestsJUnit 5 + MockitoEvery commit80% line, 70% branch
SASTCodeQL, SonarCloudPR checksZero critical/high
Dependency ScanOWASP Dependency CheckPR checksNo critical CVEs
Integration TestsSpring Test + TestContainersPR checksService layer coverage
DASTZAP ScanRelease pipelineOWASP Top 10
Penetration TestingManual + automatedQuarterlyFull application

Security Test Checklist:

□ Unit tests cover authentication logic
□ Unit tests cover authorization boundaries
□ Input validation tests include malicious payloads
□ Integration tests verify security filter chains
□ CodeQL scan passes with zero new alerts
□ OWASP Dependency Check passes
□ ZAP scan shows no new vulnerabilities
Phase 5: Secure Deployment

Deployment security controls:

yaml
# CI/CD Security Gates (GitHub Actions)
- name: Security Gate
  steps:
    - mvn test                          # All tests pass
    - mvn dependency-check:check        # No critical CVEs
    - codeql-analysis                   # No security alerts
    - sonarcloud-scan                   # Quality gate pass
    - zap-scan                          # No high findings

Deployment Checklist:

□ All CI/CD security gates pass
□ No secrets in source code or configuration
□ Database migrations reviewed for security impact
□ CloudFormation templates follow least privilege
□ Monitoring and alerting configured
□ Rollback plan documented
Phase 6: Post-Deployment

Ongoing security activities:

  • Monitor application logs for security events
  • Review Dependabot alerts weekly
  • Conduct quarterly security reviews
  • Update threat model after incidents
  • Maintain ISMS documentation currency

Decision Framework

New Feature Request
    │
    ├─→ Define security requirements
    │   └─→ Update threat model if needed
    │
    ├─→ Design with security principles
    │   └─→ Review against OWASP Top 10
    │
    ├─→ Implement with secure coding practices
    │   └─→ Follow CIA coding standards
    │
    ├─→ Test security at all levels
    │   └─→ Pass all CI/CD security gates
    │
    ├─→ Deploy with security controls
    │   └─→ Verify monitoring in place
    │
    └─→ Monitor and maintain
        └─→ Update ISMS documentation

ISMS Alignment

SDLC PhaseISO 27001 ControlsNIST CSF Functions
RequirementsA.5.8, A.8.25ID.RA, PR.IP
DesignA.8.25, A.8.26PR.IP, PR.DS
CodingA.8.28, A.8.25PR.IP, PR.DS
TestingA.8.29, A.8.33DE.CM, PR.IP
DeploymentA.8.31, A.8.32PR.IP, PR.MA
OperationsA.8.15, A.8.16DE.AE, RS.AN

References

© Hack23, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/secure-development-lifecycle of Hack23/cia.

Open the folder on GitHubat commit 6a9797b

Compare with similar skills

Secure Development Lifecycle next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Secure Development Lifecycle compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Secure Development Lifecycle this skillHack23/cia239—~1.8kAutomated safety check: PassApache-2.0
Security AuditTheDecipherist/claude-code-mastery550—~1.3kAutomated safety check: NotesMIT
Humble Header Report Analystrfc-st/humble378—~3.7kAutomated safety check: PassMIT
Pre-Commit Security Scanzereight/gitlab-mcp2k1 repos~859Automated safety check: NotesMIT
Defense In Depthsandgardenhq/sgai1373 repos~970Automated safety check: PassCustom licence
Kesekit Guidecdppcorp/KESE-KIT359—~1.4kAutomated safety check: PassMIT

Similar skills

  • Security Audit

    TheDecipherist/claude-code-mastery

    Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

    550 GitHub stars~1.3k tokensUpdated 5 mo ago
    SecurityAuto-check: notes
  • Parses reports from the humble HTTP security header analyzer and explains each finding with remediation steps for DevOps teams.

    378 GitHub stars~3.7k tokensUpdated today
    SecurityAuto-check passed
  • Pre-Commit Security Scan

    zereight/gitlab-mcp

    Runs a fast security sweep of recent code changes before a commit or PR, checking for leaked secrets, vulnerable dependencies, unsafe input handling and auth gaps.

    2k GitHub starsUsed in 1 repo~859 tokens
    SecurityAuto-check: notes
  • Defense In Depth

    sandgardenhq/sgai

    A skill your agent uses when invalid data causes failures deep in execution, requiring validation at multiple system layers - validates at every layer data passes through to make bugs structurally…

    137 GitHub starsUsed in 3 repos~970 tokens
    SecurityAuto-check passed
  • Kesekit Guide

    cdppcorp/KESE-KIT

    Generate secure coding prompts and guides for AI tools (Claude, ChatGPT, Cursor, Copilot).

    359 GitHub stars~1.4k tokensUpdated 6 mo ago
    SecurityAuto-check passed
  • Kesekit Start

    cdppcorp/KESE-KIT

    Run a security vulnerability assessment based on KISA guidelines.

    359 GitHub stars~2.3k tokensUpdated 6 mo ago
    SecurityAuto-check passed

More from Hack23/cia

All 78 skills in this repo
  • WCAG 2.1 AA compliance, ARIA attributes, keyboard navigation, screen reader optimization for accessible political data platforms

    239 GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Advanced chart types, D3.js/Vaadin Charts patterns, political data visualization, time series analysis

    239 GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • AI Governance

    Hack23/cia

    AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents

    239 GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • API Integration

    Hack23/cia

    External API integration patterns, retry logic, circuit breakers, caching, rate limiting for government data APIs

    239 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • AWS CloudWatch metrics, alarms, dashboards, log insights, and application monitoring for the CIA platform

    239 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • AWS security best practices, VPC security, IAM, KMS, CloudTrail, GuardDuty for CIA platform deployment

    239 GitHub stars~2.3k tokensUpdated today
    Auto-check passed

Questions about Secure Development Lifecycle

What does Secure Development Lifecycle do?

Secure SDLC phases, security requirements, secure coding practices, and security testing integration for the CIA platform. Secure Development Lifecycle is an agent skill from Hack23/cia.

When should I use Secure Development Lifecycle?

Secure Development Lifecycle fits situations like: tasks that involve Secure coding.

How do I install Secure Development Lifecycle in Claude Code?

Run `npx skills add Hack23/cia --skill secure-development-lifecycle -a claude-code`. Or copy the skill folder (.github/skills/secure-development-lifecycle in Hack23/cia) into .claude/skills/secure-development-lifecycle in your project. Claude Code loads it when a task matches its description.

How do I install Secure Development Lifecycle in Codex?

Run `npx skills add Hack23/cia --skill secure-development-lifecycle -a codex`. Or copy the skill folder (.github/skills/secure-development-lifecycle in Hack23/cia) into .agents/skills/secure-development-lifecycle in your project. Codex loads it when a task matches its description.

Can I use Secure Development Lifecycle in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Hack23/cia --skill secure-development-lifecycle -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/secure-development-lifecycle, .gemini/skills/secure-development-lifecycle, .github/skills/secure-development-lifecycle and .opencode/skills/secure-development-lifecycle in your project.

What does Secure Development Lifecycle need to run?

SKILL.md names no scripts, command-line tools or credentials: Secure Development Lifecycle is instructions for the agent only.

Does Secure Development Lifecycle access the network?

SKILL.md names 4 domains. As links in the text: owasp.org, csrc.nist.gov, github.com and iso.org. This is read from the text; nothing was executed.

Is Secure Development Lifecycle safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Secure Development Lifecycle use?

Secure Development Lifecycle is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Secure Development Lifecycle use?

About 1.8k tokens (SKILL.md is roughly 7.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Secure Development Lifecycle?

Skills that share tags, products or a category with Secure Development Lifecycle: Security Audit (TheDecipherist/claude-code-mastery, 550 stars), Humble Header Report Analyst (rfc-st/humble, 378 stars), Pre-Commit Security Scan (zereight/gitlab-mcp, 2k stars) and Defense In Depth (sandgardenhq/sgai, 137 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Secure Development Lifecycle?

Hack23 (a GitHub organization) maintains it in Hack23/cia, which has 239 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on October 6, 2026.

Source: Hack23/cia on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.