Agent skill

Guidewire Security And Rbac

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Lock down a Guidewire Cloud API integration so it survives a SOC 2 audit, an NAIC Model Audit Rule review, and a real-world incident — least-privilege role design, encrypted committed secrets via…

MITAuto-check: notesBackend & APIs

Install Guidewire Security And Rbac

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill guidewire-security-and-rbac -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace guidewire-security-and-rbac --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/guidewire-security-and-rbac .claude/skills/guidewire-security-and-rbac && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
guidewire-security-and-rbac
GitHub stars
2.8k
Token cost
~3.5k tokens
SKILL.md length
1,245 words
Files
3 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Lock down a Guidewire Cloud API integration so it survives a SOC 2 audit, an NAIC Model Audit Rule review, and a real-world incident — least-privilege role design, encrypted committed secrets via…

  • Works in 6 steps: Encrypted committed secrets via SOPS + age → Least-privilege roles per Service… → PII redaction in logs → …
  • Designing the security posture for a new integration
  • SKILL.md covers Overview, Prerequisites, Instructions and Output, plus 4 more sections
  • Calls git, brew and apt; needs GW_CLIENT_SECRET

What it does

Guidewire Security And Rbac is an agent skill from jeremylongshore/tons-of-skills-marketplace. Lock down a Guidewire Cloud API integration so it survives a SOC 2 audit, an NAIC Model Audit Rule review, and a real-world incident — least-privilege role design, encrypted committed secrets via SOPS+age, PII redaction in logs (SSN/DOB/claim narrative), audit-trail capture, cross-tenant isolation for multi-carrier integrations, and detect-and-rotate response to token leaks. Use when designing the security posture for a new integration, hardening an existing one before audit, or responding to a leaked credential…

Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/API_REFERENCE.md` and `references/implementation-guide.md`). Compatibility notes: Designed for Claude Code

It sits in Backend & APIs, covering Authorization and RBAC, Operations and SOPs and Multi-tenancy. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Designing the security posture for a new integration
  • Hardening an existing one before audit
  • Responding to a leaked credential
  • With guidewire security

Example prompts

  • “guidewire security”
  • “guidewire rbac”
  • “guidewire pii redaction”
  • “/guidewire-security-and-rbac”

Requirements

  • A credential in GW_CLIENT_SECRET
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Bash(sops:*), Bash(age:*), Bash(curl:*), Grep, Glob

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Encrypted committed secrets via SOPS + age
  2. Least-privilege roles per Service Application
  3. PII redaction in logs
  4. Audit trail of integration actions
  5. Cross-tenant isolation for multi-carrier integrations
  6. Detect-and-rotate response to suspected secret leak

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Bash(sops:*)
    • Bash(age:*)
    • Bash(curl:*)
    • Grep
    • Glob

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • brew
    • apt
    • mise

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com
    • owasp.org
    • aicpa-cima.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GW_CLIENT_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Guidewire Security And Rbac loads about 3.5k tokens when it runs, and up to ~6.2k if it reads all its reference files. Until then it costs about 169 tokens; SKILL.md has 1,245 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~169
When it runs · the whole SKILL.md, loaded when a task matches
~3.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:26
    1. **Plaintext `.env` in the repo** — a `git push` to a public mirror leaks live credentials; the only defense is to nev
  • NoteMentions a .env fileSKILL.md:45
    Plaintext `.env` files committed to a repo are the single largest source of credential leaks in the SaaS world. SOPS + a
  • NoteMentions a .env fileSKILL.md:48
    # writes .sops.yaml + .env.sops + scripts/sops-env (idempotent)
  • NoteMentions a .env fileSKILL.md:159
    nvironment age recipients; no plaintext `.env` files anywhere in the tree.
  • NoteMentions a .env fileSKILL.md:221
    | Plaintext `.env` discovered in git history | committed before SOPS adoption | rotate every credential in the leaked fi

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 1,245 words, ~3,496 tokens.

Download SKILL.mdSave it as .claude/skills/guidewire-security-and-rbac/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
guidewire-security-and-rbac
description
Lock down a Guidewire Cloud API integration so it survives a SOC 2 audit, an NAIC Model Audit Rule review, and a real-world incident — least-privilege role design, encrypted committed secrets via SOPS+age, PII redaction in logs (SSN/DOB/claim narrative), audit-trail capture, cross-tenant isolation for multi-carrier integrations, and detect-and-rotate response to token leaks. Use when designing the security posture for a new integration, hardening an existing one before audit, or responding to a leaked credential. Trigger with "guidewire security", "guidewire rbac", "guidewire pii redaction", "guidewire audit trail", "guidewire secret leak".
allowed-tools
Read, Write, Edit, Bash(sops:*), Bash(age:*), Bash(curl:*), Grep, Glob
compatibility
Designed for Claude Code
version
1.26.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
guidewire, security, rbac, pii, sops, audit

Guidewire Security and RBAC

Overview

Build the security posture an integration needs in production: secrets that cannot leak from the repo, roles that cannot escalate beyond their job, logs that cannot exfiltrate PII, and an audit trail that satisfies SOC 2 and NAIC Model Audit Rule reviewers. This skill is the application of generic security practice to the specific shape of Guidewire Cloud API — claim and policy data carry regulated PII; a leaked client_secret can read or write a carrier's entire book of business; carriers operate under state-level insurance regulator scrutiny.

Five real-world failures this skill prevents:

  1. Plaintext .env in the repo — a git push to a public mirror leaks live credentials; the only defense is to never have plaintext in the tree, full stop.
  2. Over-scoped Service Application — every integration starts with pc.account.write "to make development easier" and is never narrowed; the audit finding cites OWASP A01 broken access control.
  3. PII in observability — console.log(claim) dumps SSN, DOB, claim narrative, and phone numbers into the logging pipeline, where they replicate to every downstream tool the company uses.
  4. No audit trail of what the integration did — security review asks "what did this service touch in the last 90 days" and the answer is "everything in the access log, but we cannot tell which actor"; the audit fails.
  5. Cross-tenant data bleed — a multi-tenant integration uses one set of credentials per environment instead of per tenant; a bug in tenant routing leaks Carrier A's data into Carrier B's response.

Prerequisites

  • A working auth + SDK layer per guidewire-install-auth and guidewire-sdk-patterns
  • sops and age installed locally (brew install sops age / apt install sops / mise install age)
  • Access to GCC for the integration's Service Application configuration
  • A logging/observability stack the integration writes to (Datadog, Splunk, ELK, or similar) — required for the redaction patterns to apply

Instructions

Build the posture in this order. Each layer addresses one of the five failures listed in Overview.

1. Encrypted committed secrets via SOPS + age

Plaintext .env files committed to a repo are the single largest source of credential leaks in the SaaS world. SOPS + age allows secrets to live in the repo as ciphertext that only holders of the age private key can read. The audit trail of "who rotated what when" comes free with git log.

bash
sops-init                                    # writes .sops.yaml + .env.sops + scripts/sops-env (idempotent)
sops secrets.prod.sops.yaml                  # interactive edit; saves re-encrypted
git add secrets.prod.sops.yaml && git commit -m "chore(secrets): rotate gw client secret"

In the runtime, decrypt via the anchored regex pattern (do not use the naive sed 's/^/export /' — see guidewire-install-auth for the bare-export-leak failure mode):

bash
eval "$(sops -d secrets.prod.sops.yaml | sed -nE 's/^([A-Za-z_][A-Za-z0-9_]*)=(.*)$/export \1=\2/p')"

Per-environment recipient lists in .sops.yaml mean dev keys cannot decrypt prod secrets — limit blast radius of a compromised dev workstation.

2. Least-privilege roles per Service Application

In GCC > Identity & Access > Applications > [your-app] > Permissions, assign only the roles the integration actually needs. A read-only reporting integration should hold pc.account.read and pc.policy.read only; a webhook event consumer needs zero write roles.

Reporting integration:        pc.account.read, pc.policy.read, cc.claim.read
Broker portal (read+quote):   pc.account.read, pc.account.write, pc.submission.write
Renewal job:                  pc.policy.read, pc.policy.write
Claims FNOL intake:           cc.claim.write, cc.contact.write
Webhook event consumer:       (no Cloud API roles — just receives App Events)

Validate the issued token carries only the expected scopes on every refresh (guidewire-install-auth's scope-drift gate). A token with extra scopes is a configuration error; alert and treat as an incident.

3. PII redaction in logs

Guidewire claim and contact resources carry regulated PII: SSN, date of birth, driver's license number, claim narrative, phone, email, address. Redact at the logging boundary, not in the calling code (which always misses cases). Apply the redactor to every structured log entry the integration emits.

typescript
const PII_PATHS = [
  "ssn", "taxId", "dateOfBirth", "driversLicenseNumber",
  "primaryPhone.phoneNumber", "workPhone.phoneNumber", "primaryEmail",
  "addressLine1", "addressLine2", "description", // claim narrative
];

export function redactPii<T extends object>(record: T): T {
  const clone = JSON.parse(JSON.stringify(record));
  for (const path of PII_PATHS) {
    setByPath(clone, path, redactValue(getByPath(clone, path)));
  }
  return clone;
}

function redactValue(v: unknown): string | unknown {
  if (typeof v !== "string" || !v) return v;
  if (/^\d{3}-?\d{2}-?\d{4}$/.test(v)) return "***-**-****";       // SSN
  if (/^\d{4}-\d{2}-\d{2}/.test(v)) return v.slice(0, 4) + "-**-**"; // DOB → year only
  if (v.length <= 4) return "***";
  return v.slice(0, 2) + "***" + v.slice(-2);
}

Wire the redactor into the logger transport (Pino redact, Winston format, OpenTelemetry log processor) so every log entry passes through it before serialization. Per-call console.log(redactPii(claim)) works in theory and fails in practice — engineers forget.

4. Audit trail of integration actions

Every state-mutating Cloud API call should leave a row in an internal audit table the integration owns. Cloud API has its own audit, but it cannot tell investigators which logical operation drove a request, only that the Service Application made the call.

sql
CREATE TABLE integration_audit (
  id UUID PRIMARY KEY,
  correlation_id UUID NOT NULL,
  actor TEXT NOT NULL,                 -- the upstream user, broker, or job triggering the call
  service_app TEXT NOT NULL,           -- the GCC Service Application id
  api_method TEXT NOT NULL,            -- POST / PATCH / DELETE
  api_path TEXT NOT NULL,              -- /pc/rest/v1/policies/pc:8001
  resource_id TEXT,                    -- post-response id
  idempotency_key UUID NOT NULL,
  status_code INT NOT NULL,
  reason TEXT,                         -- "renewal-window-open", "broker-quote-flow", etc.
  at TIMESTAMPTZ NOT NULL DEFAULT now()
);

Each row pairs to one Cloud API call. SOC 2 reviewers ask "show me every write this integration made on behalf of broker acme-insurance in March"; this table makes the answer a SQL query, not a forensic exercise.

5. Cross-tenant isolation for multi-carrier integrations

If the integration serves more than one carrier, every carrier gets:

  • A separate Service Application registration in GCC (separate client_id/client_secret)
  • A separate entry in secrets.[carrier-slug].sops.yaml encrypted to a tenant-specific recipient
  • A separate row in tenant-routing config that maps inbound requests to outbound credentials
  • A separate scope assignment audited per the role table above

Sharing one Service Application across tenants creates legal and contractual exposure beyond the technical risk; a single compromised credential reveals every tenant's data, and an audit finding will cite SOC 2 CC6.1 (logical access controls).

Show full SKILL.md (488 more words)Show less
6. Detect-and-rotate response to suspected secret leak

When a secret is suspected leaked (a developer pasted it into a Slack message, a CI log captured it, a public commit briefly contained it):

bash
# 1. Rotate immediately in GCC — generates a new client_secret
# 2. Update the encrypted secret file
sops secrets.prod.sops.yaml             # set GW_CLIENT_SECRET to the new value
git commit -m "rotate(secrets): GW client secret — leak suspected $(date -Iseconds)"
# 3. Deploy to all environments
# 4. Use dual-secret window (per guidewire-install-auth) so in-flight requests do not fail
# 5. Audit Cloud API access logs for unauthorized calls during the leak window
# 6. Document the incident in the audit table per step 4

Do not "wait until business hours" — credential leaks compound by the minute. The rotation is reversible; the data exfiltration is not.

Output

A production-grade security posture ships with all of the following:

  • All secrets stored as secrets.*.sops.yaml files committed to git, encrypted to per-environment age recipients; no plaintext .env files anywhere in the tree.
  • Service Application roles assigned per least privilege, validated on every token refresh by the scope-drift gate.
  • A logger configured to apply redactPii() to every structured log entry before serialization.
  • An integration_audit table populated synchronously with every state-mutating Cloud API call.
  • Per-tenant Service Applications and secret files for any multi-carrier integration.
  • A documented detect-and-rotate runbook with a target rotation time of <30 minutes from suspicion to deploy.

Examples

Example 1 — .sops.yaml recipient layering
yaml
creation_rules:
  - path_regex: secrets\.dev\.sops\.yaml$
    age: age1devkey...,age1leadkey...
  - path_regex: secrets\.uat\.sops\.yaml$
    age: age1uatkey...,age1leadkey...
  - path_regex: secrets\.prod\.sops\.yaml$
    age: age1prodkey...,age1leadkey...

A developer's age key decrypts dev only; the lead's key decrypts every environment for incident response. Rotation of an environment's age recipient is sops updatekeys secrets.<env>.sops.yaml.

Example 2 — Pino redactor wiring
typescript
import pino from "pino";
const log = pino({
  redact: {
    paths: [
      "*.ssn", "*.taxId", "*.dateOfBirth",
      "*.primaryPhone.phoneNumber", "*.primaryEmail",
      "*.description",
    ],
    censor: "[REDACTED]",
  },
});
log.info({ claim: claimResource }, "claim received");
Example 3 — Audit row on a write
typescript
await db.insert("integration_audit", {
  id: crypto.randomUUID(),
  correlation_id: ctx.correlationId,
  actor: ctx.user.id,
  service_app: process.env.GW_CLIENT_ID,
  api_method: "POST",
  api_path: "/pc/rest/v1/policies/pc:8001/endorse",
  resource_id: response.data.id,
  idempotency_key: idempotencyKey,
  status_code: 200,
  reason: "broker-portal-mid-term-coverage-add",
});

Error Handling

SymptomCauseSolution
403 Forbidden despite valid tokenscope drift — GCC admin removed a rolescope-drift gate alerts on every refresh; not a transport failure, surface as incident
Plaintext .env discovered in git historycommitted before SOPS adoptionrotate every credential in the leaked file immediately; rewrite history with git filter-repo if the leak is recent
Logger emits SSN to SplunkredactPii not wired into the transportadd at the logger config, not at call sites; remove the per-call redactPii() in favor of transport-level
SOPS commit accidentally encrypted to wrong recipient.sops.yaml regex did not matchrun sops updatekeys on the affected file; recipients are visible in the YAML metadata
Bare export in cron mail leaks every env varnaive sed 's/^/export /' instead of anchored regexswitch to sed -nE 's/^([A-Za-z_][A-Za-z0-9_]*)=(.*)$/export \1=\2/p'
Audit query "what did integration do for broker X last month" returns nothingaudit table not populatedwire integration_audit insert into every write helper; backfill is impossible
One client_secret used across two carriersshared Service Applicationsplit immediately; rotate both halves to scope the blast radius
Token in a CI logsecret printed accidentally during deploymentrotate via the detect-and-rotate runbook; audit access during the leak window

For deeper coverage (Vault Agent integration, dynamic secrets, token-binding, federated identity, FIPS-140 trust stores), see implementation guide and API reference.

See Also

  • guidewire-install-auth — the auth layer this hardens; scope-drift gate, dual-secret rotation
  • guidewire-sdk-patterns — error mapping that surfaces 403 as a structured exception this skill alerts on
  • guidewire-observability-and-incident-response — emits the alerts this skill's audit table powers
  • guidewire-ci-cd-pipeline — promotes encrypted secrets through environments without plaintext exposure

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in skills/.curated/guidewire-security-and-rbac of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/API_REFERENCE.md
  • references/implementation-guide.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Guidewire Security And Rbac next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Guidewire Security And Rbac compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Guidewire Security And Rbac this skilljeremylongshore/tons-of-skills-marketplace2.8k—~3.5kAutomated safety check: NotesMIT
Abp Authorizationabpframework/abp14k—~1.3kAutomated safety check: PassLGPL-3.0
Django Access Reviewgetsentry/skills1k3 repos~2.6kAutomated safety check: NotesApache-2.0
Supercheck Security Authsupercheck-io/supercheck215—~1.2kAutomated safety check: PassAGPL-3.0
Backend AI Guidelablup/backend.ai-webui1331 repos~1.8kAutomated safety check: PassLGPL-3.0
Arandu Shared Modules Guidearandu-io/arandu281—~1.8kAutomated safety check: PassMIT

Similar skills

  • Abp Authorization

    abpframework/abp

    ABP permission system - PermissionDefinitionProvider, [Authorize] attribute, CheckPolicyAsync, IsGrantedAsync, ICurrentUser, IPermissionManager, multi-tenancy side.

    14k GitHub stars~1.3k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Django Access Review

    getsentry/skills

    Official

    Django access control and IDOR security review. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 3 repos~2.6k tokens
    Backend & APIsAuto-check: notes
  • Supercheck Security Auth

    supercheck-io/supercheck

    Work on Supercheck authentication, RBAC, tenant isolation, sessions, API and trigger keys, invitations, project membership, project variables, OAuth, super-admin behavior, SSRF, or…

    215 GitHub stars~1.2k tokensUpdated today
    Backend & APIsAuto-check passed
  • Backend AI Guide

    lablup/backend.ai-webui

    Expert guide for Backend.AI distributed computing platform. An agent skill from lablup/backend.ai-webui.

    133 GitHub starsUsed in 1 repo~1.8k tokens
    Backend & APIsAuto-check passed
  • Decides whether a feature belongs in the application or in one of five shared Arandu modules before adding permissions, wallets, tags, Markdown rendering or API docs.

    281 GitHub stars~1.8k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Cognee Permissions

    topoteretes/cognee

    A skill your agent uses when working with cognee's users, permissions, and multi-tenancy — creating users, tenants and roles, sharing datasets (read/write/delete/share grants), acting as a specific…

    32k GitHub stars~3.6k tokensUpdated yesterday
    Backend & APIsAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Categories

Questions about Guidewire Security And Rbac

What does Guidewire Security And Rbac do?

Lock down a Guidewire Cloud API integration so it survives a SOC 2 audit, an NAIC Model Audit Rule review, and a real-world incident — least-privilege role design, encrypted committed secrets via…. Guidewire Security And Rbac is an agent skill from jeremylongshore/tons-of-skills-marketplace. Lock down a Guidewire Cloud API integration so it survives a SOC 2 audit, an NAIC Model Audit Rule review, and a real-world incident — least-privilege role design, encrypted committed secrets via SOPS+age, PII redaction in logs (SSN/DOB/claim narrative), audit-trail capture, cross-tenant isolation for multi-carrier integrations, and detect-and-rotate response to token leaks.

When should I use Guidewire Security And Rbac?

Guidewire Security And Rbac fits situations like: designing the security posture for a new integration; hardening an existing one before audit; responding to a leaked credential; with guidewire security.

How do I install Guidewire Security And Rbac in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill guidewire-security-and-rbac -a claude-code`. Or copy the skill folder (skills/.curated/guidewire-security-and-rbac in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/guidewire-security-and-rbac in your project. Claude Code loads it when a task matches its description.

How do I install Guidewire Security And Rbac in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill guidewire-security-and-rbac -a codex`. Or copy the skill folder (skills/.curated/guidewire-security-and-rbac in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/guidewire-security-and-rbac in your project. Codex loads it when a task matches its description.

Can I use Guidewire Security And Rbac in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill guidewire-security-and-rbac -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/guidewire-security-and-rbac, .gemini/skills/guidewire-security-and-rbac, .github/skills/guidewire-security-and-rbac and .opencode/skills/guidewire-security-and-rbac in your project.

What does Guidewire Security And Rbac need to run?

Going by SKILL.md and its folder, Guidewire Security And Rbac needs the command-line tools its instructions call (git, brew, apt and mise) and credentials named GW_CLIENT_SECRET. Our summary lists: A credential in GW_CLIENT_SECRET. Its frontmatter pre-approves these tools: Read, Write, Edit, Bash(sops:*), Bash(age:*), Bash(curl:*), Grep, Glob. Compatibility (from SKILL.md): Designed for Claude Code.

Does Guidewire Security And Rbac access the network?

SKILL.md names 3 domains. As links in the text: github.com, owasp.org and aicpa-cima.com. This is read from the text; nothing was executed.

Is Guidewire Security And Rbac safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Guidewire Security And Rbac use?

Guidewire Security And Rbac is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Guidewire Security And Rbac use?

About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.7k tokens, read only when the agent opens those files.

What are the alternatives to Guidewire Security And Rbac?

Skills that share tags, products or a category with Guidewire Security And Rbac: Abp Authorization (abpframework/abp, 14k stars), Django Access Review (getsentry/skills, 1k stars), Supercheck Security Auth (supercheck-io/supercheck, 215 stars) and Backend AI Guide (lablup/backend.ai-webui, 133 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Guidewire Security And Rbac?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.