Agent skill

Security By Design

by Hack23 in Hack23/cia

Threat modeling before coding, STRIDE methodology, defense in depth, security controls in SDLC

Apache-2.0Auto-check passedSecurity

Install Security By Design

skills CLI
$ npx skills add Hack23/cia --skill security-by-design -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Hack23/cia security-by-design --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/security-by-design .claude/skills/security-by-design && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-by-design
GitHub stars
239
Token cost
~1.9k tokens
SKILL.md length
214 words
Files
1
Skills in repo
78
Repo updated
First seen
Licence
Apache-2.0

At a glance

Threat modeling before coding, STRIDE methodology, defense in depth, security controls in SDLC

  • Tasks that involve Threat modeling
  • SKILL.md covers Purpose, When to Use This Skill, Security in SDLC Phases and STRIDE Threat Modeling, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Tasks that involve Secure coding

What it does

Security By Design is an agent skill from Hack23/cia. Threat modeling before coding, STRIDE methodology, defense in depth, security controls in SDLC

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Threat modeling and Secure coding. The repository describes itself as: Citizen Intelligence Agency. Open-source intelligence platform analyzing Swedish political activities using AI and data visualization. Tracks politicians, government… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Threat modeling
  • Tasks that involve Secure coding

Example prompts

  • “/security-by-design”

What it can do on your machine

Read from SKILL.md and the folder at commit 6a9797b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are java).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com
    • owasp.org
    • learn.microsoft.com
    • csrc.nist.gov

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security By Design loads about 1.9k tokens when it runs. Until then it costs about 28 tokens; SKILL.md has 214 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~28
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Hack23/cia at commit 6a9797b, republished under its Apache-2.0 licence (© Hack23). 214 words, ~1,910 tokens.

Download SKILL.mdSave it as .claude/skills/security-by-design/SKILL.md (or your agent's skills folder).
name
security-by-design
description
Threat modeling before coding, STRIDE methodology, defense in depth, security controls in SDLC
license
Apache-2.0

Security by Design Skill

Purpose

This skill integrates security into every phase of the CIA platform's software development lifecycle (SDLC). It ensures threats are identified and mitigated before code is written, following defense-in-depth principles aligned with Hack23 ISMS Secure Development Policy.

When to Use This Skill

Apply this skill when:

  • ✅ Starting a new feature or user story
  • ✅ Designing API endpoints or data flows
  • ✅ Creating architecture or design documents
  • ✅ Writing acceptance criteria for security stories
  • ✅ Reviewing pull requests for security implications
  • ✅ Planning sprint work involving sensitive data
  • ✅ Conducting design reviews before implementation

Do NOT use for:

  • ❌ Post-incident forensics (use incident-response skill)
  • ❌ Runtime security monitoring (use aws-cloudwatch-monitoring)
  • ❌ Code-level vulnerability scanning (use secure-code-review)

Security in SDLC Phases

SDLC Phase          Security Activity
│
├─ REQUIREMENTS
│  ├─ Identify security requirements (abuse cases)
│  ├─ Define data classification for new features
│  └─ Document compliance requirements (GDPR, NIS2)
│
├─ DESIGN
│  ├─ Threat model using STRIDE
│  ├─ Define trust boundaries
│  ├─ Select security controls
│  └─ Review architecture for defense in depth
│
├─ IMPLEMENTATION
│  ├─ Follow secure coding standards
│  ├─ Use approved libraries and frameworks
│  ├─ Implement input validation at boundaries
│  └─ Apply principle of least privilege
│
├─ TESTING
│  ├─ Security unit tests
│  ├─ SAST scanning (CodeQL, SonarCloud)
│  ├─ DAST scanning (ZAP)
│  └─ Dependency vulnerability check (OWASP)
│
├─ DEPLOYMENT
│  ├─ Security configuration review
│  ├─ Infrastructure hardening verification
│  ├─ Secrets management validation
│  └─ Monitoring and alerting setup
│
└─ MAINTENANCE
   ├─ Vulnerability patching cadence
   ├─ Security incident response
   ├─ Periodic threat model updates
   └─ Dependency update reviews

STRIDE Threat Modeling

Quick-Start Template for CIA Features
Feature: [Name]
Data Classification: [PUBLIC/INTERNAL/CONFIDENTIAL/RESTRICTED]
Trust Boundary: [User→App / App→DB / App→ExternalAPI]

┌─────────────┬──────────────────────────────────────────┐
│ STRIDE      │ Assessment                               │
├─────────────┼──────────────────────────────────────────┤
│ Spoofing    │ Can an attacker impersonate a user?       │
│ Tampering   │ Can data be modified in transit/storage?  │
│ Repudiation │ Can actions be denied without proof?      │
│ Info Disc.  │ Can sensitive data leak?                  │
│ DoS         │ Can service be overwhelmed?               │
│ Elev. Priv. │ Can a user gain unauthorized access?      │
└─────────────┴──────────────────────────────────────────┘
CIA Platform Example: Politician Dashboard
Feature: Politician Risk Score Dashboard
Data Classification: INTERNAL
Trust Boundaries: Browser→Vaadin→Service→Database

Spoofing:
  Threat: Unauthenticated access to risk scores
  Control: Spring Security authentication required
  Code: @PreAuthorize("hasRole('USER')")

Tampering:
  Threat: Manipulation of risk score algorithm inputs
  Control: Read-only database transactions for analysis
  Code: @Transactional(readOnly = true)

Repudiation:
  Threat: User denies viewing sensitive risk data
  Control: Audit logging of all dashboard access
  Code: AuditService.logAccess(userId, "RISK_DASHBOARD")

Information Disclosure:
  Threat: Risk scores leaked to unauthorized users
  Control: Role-based access, no client-side caching
  Code: Cache-Control: no-store, Pragma: no-cache

Denial of Service:
  Threat: Complex queries overloading database
  Control: Query timeout, connection pool limits
  Code: spring.datasource.hikari.connectionTimeout=30000

Elevation of Privilege:
  Threat: Regular user accessing admin risk controls
  Control: Method-level security annotations
  Code: @Secured("ROLE_ADMIN")

Defense in Depth Layers

Layer 1: NETWORK
├─ AWS VPC with private subnets
├─ Security groups (least privilege)
├─ WAF rules for common attacks
└─ DDoS protection (AWS Shield)

Layer 2: APPLICATION
├─ Spring Security filter chain
├─ CSRF protection enabled
├─ Content Security Policy headers
└─ Rate limiting per client

Layer 3: DATA
├─ Input validation at every boundary
├─ Parameterized queries (JPA/Hibernate)
├─ Output encoding (Vaadin auto-escapes)
└─ Encryption at rest (AES-256, KMS)

Layer 4: IDENTITY
├─ Strong authentication (bcrypt, cost 12)
├─ Role-based access control (RBAC)
├─ Session management (secure cookies)
└─ Principle of least privilege

Layer 5: MONITORING
├─ Security event logging (CloudWatch)
├─ Intrusion detection (GuardDuty)
├─ Vulnerability scanning (CodeQL, OWASP)
└─ Incident response procedures

Security Controls Checklist

For Every New Feature
Pre-Implementation:
□ Threat model completed (STRIDE)
□ Data classification assigned
□ Security requirements documented
□ Trust boundaries identified

During Implementation:
□ Input validation at all entry points
□ Output encoding for all user-displayed data
□ Authentication required for protected resources
□ Authorization checks at service layer
□ Parameterized queries for database access
□ Secrets managed via environment variables
□ Error messages don't leak internal details
□ Logging includes security-relevant events

Post-Implementation:
□ CodeQL scan passes with no high/critical findings
□ OWASP dependency check passes
□ Security unit tests written and passing
□ Code review with security focus completed
Secure Defaults
java
// ✅ Spring Security configuration with secure defaults
@Configuration
@EnableWebSecurity
public class SecurityConfig {

    @Bean
    public SecurityFilterChain filterChain(HttpSecurity http) throws Exception {
        http
            .headers(headers -> headers
                .contentSecurityPolicy(csp -> csp
                    .policyDirectives("default-src 'self'"))
                .frameOptions(frame -> frame.deny())
                .httpStrictTransportSecurity(hsts -> hsts
                    .maxAgeInSeconds(31536000)
                    .includeSubDomains(true)))
            .sessionManagement(session -> session
                .sessionCreationPolicy(SessionCreationPolicy.IF_REQUIRED)
                .maximumSessions(1))
            .csrf(csrf -> csrf.csrfTokenRepository(
                CookieCsrfTokenRepository.withHttpOnlyFalse()));
        return http.build();
    }
}

ISMS Alignment

ControlRequirementSecurity-by-Design Activity
ISO 27001 A.8.25Secure development lifecycleSTRIDE per feature
ISO 27001 A.8.26Application security requirementsSecurity user stories
ISO 27001 A.8.28Secure codingApproved coding patterns
NIST CSF PR.DSData securityEncryption by default
CIS Control 16Application software securitySAST/DAST in pipeline
NIS2 Art. 21Cybersecurity risk managementThreat modeling

References

© Hack23, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/security-by-design of Hack23/cia.

Open the folder on GitHubat commit 6a9797b

Compare with similar skills

Security By Design next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security By Design compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security By Design this skillHack23/cia239—~1.9kAutomated safety check: PassApache-2.0
Security Hardeningancoleman/ai-design-components526—~3.5kAutomated safety check: PassMIT
Architecting Securityancoleman/ai-design-components526—~6.3kAutomated safety check: PassMIT
Senior Securityborghei/Claude-Skills874—~1.8kAutomated safety check: PassMIT
Goericrisco/rsc-harness156—~3.9kAutomated safety check: PassMIT
Security And Hardeningpenpot/penpot61k6 repos~4.7kAutomated safety check: NotesMPL-2.0

Similar skills

  • Security Hardening

    ancoleman/ai-design-components

    Reduces attack surface across OS, container, cloud, network, and database layers using CIS Benchmarks and zero-trust principles.

    526 GitHub stars~3.5k tokensUpdated 10 mo ago
    SecurityAuto-check passed
  • Architecting Security

    ancoleman/ai-design-components

    Design comprehensive security architectures using defense-in-depth, zero trust principles, threat modeling (STRIDE, PASTA), and control frameworks (NIST CSF, CIS Controls, ISO 27001).

    526 GitHub stars~6.3k tokensUpdated 10 mo ago
    SecurityAuto-check passed
  • Senior Security

    borghei/Claude-Skills

    STRIDE threat modeling, DREAD risk scoring, secret detection, and secure architecture design.

    874 GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check passed
  • Go

    ericrisco/rsc-harness

    A skill your agent uses when writing, reviewing, testing, or shipping Go code and HTTP services: idioms, %w error wrapping, goroutine/context/errgroup concurrency, net/http 1.22 routing, log/slog…

    156 GitHub stars~3.9k tokensUpdated today
    SecurityAuto-check passed
  • Hardens code against vulnerabilities. An agent skill from penpot/penpot.

    61k GitHub starsUsed in 6 repos~4.7k tokens
    SecurityAuto-check: notes
  • Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

    74k GitHub starsUsed in 2 repos~823 tokens
    SecurityAuto-check passed

More from Hack23/cia

All 78 skills in this repo
  • WCAG 2.1 AA compliance, ARIA attributes, keyboard navigation, screen reader optimization for accessible political data platforms

    239 GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Advanced chart types, D3.js/Vaadin Charts patterns, political data visualization, time series analysis

    239 GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • AI Governance

    Hack23/cia

    AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents

    239 GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • API Integration

    Hack23/cia

    External API integration patterns, retry logic, circuit breakers, caching, rate limiting for government data APIs

    239 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • AWS CloudWatch metrics, alarms, dashboards, log insights, and application monitoring for the CIA platform

    239 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • AWS security best practices, VPC security, IAM, KMS, CloudTrail, GuardDuty for CIA platform deployment

    239 GitHub stars~2.3k tokensUpdated today
    Auto-check passed

Categories

Questions about Security By Design

What does Security By Design do?

Threat modeling before coding, STRIDE methodology, defense in depth, security controls in SDLC. Security By Design is an agent skill from Hack23/cia.

When should I use Security By Design?

Security By Design fits situations like: tasks that involve Threat modeling; tasks that involve Secure coding.

How do I install Security By Design in Claude Code?

Run `npx skills add Hack23/cia --skill security-by-design -a claude-code`. Or copy the skill folder (.github/skills/security-by-design in Hack23/cia) into .claude/skills/security-by-design in your project. Claude Code loads it when a task matches its description.

How do I install Security By Design in Codex?

Run `npx skills add Hack23/cia --skill security-by-design -a codex`. Or copy the skill folder (.github/skills/security-by-design in Hack23/cia) into .agents/skills/security-by-design in your project. Codex loads it when a task matches its description.

Can I use Security By Design in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Hack23/cia --skill security-by-design -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-by-design, .gemini/skills/security-by-design, .github/skills/security-by-design and .opencode/skills/security-by-design in your project.

What does Security By Design need to run?

SKILL.md names no scripts, command-line tools or credentials: Security By Design is instructions for the agent only.

Does Security By Design access the network?

SKILL.md names 4 domains. As links in the text: github.com, owasp.org, learn.microsoft.com and csrc.nist.gov. This is read from the text; nothing was executed.

Is Security By Design safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security By Design use?

Security By Design is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security By Design use?

About 1.9k tokens (SKILL.md is roughly 7.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security By Design?

Skills that share tags, products or a category with Security By Design: Security Hardening (ancoleman/ai-design-components, 526 stars), Architecting Security (ancoleman/ai-design-components, 526 stars), Senior Security (borghei/Claude-Skills, 874 stars) and Go (ericrisco/rsc-harness, 156 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security By Design?

Hack23 (a GitHub organization) maintains it in Hack23/cia, which has 239 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on October 6, 2026.

Source: Hack23/cia on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.