Agent skill

Workhuman Security Basics

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Define shared-responsibility security controls for Workhuman identity, workforce data, recognition, awards, Store, and integrations.

MITAuto-check passedLegal & Compliance

Install Workhuman Security Basics

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill workhuman-security-basics -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace workhuman-security-basics --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/workhuman-security-basics .claude/skills/workhuman-security-basics && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
workhuman-security-basics
GitHub stars
2.8k
Token cost
~1.1k tokens
SKILL.md length
400 words
Files
1
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Define shared-responsibility security controls for Workhuman identity, workforce data, recognition, awards, Store, and integrations.

  • Works in 8 steps: Diagram identity, worker, recognition,… → Classify fields and define purpose,… → Review SSO, lifecycle, privileges,… → …
  • Reviewing threats
  • SKILL.md covers Overview, Prerequisites, Tool Discipline and Current Contract, plus 8 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Workhuman Security Basics is an agent skill from jeremylongshore/tons-of-skills-marketplace. Define shared-responsibility security controls for Workhuman identity, workforce data, recognition, awards, Store, and integrations. Use when reviewing threats or hardening controls. Trigger with "secure a Workhuman integration".

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Designed for Claude Code; security, privacy, SSO, privilege, retention, and integration changes require accountable owner approval

It sits in Legal & Compliance. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Reviewing threats
  • Hardening controls
  • With secure a Workhuman integration

Example prompts

  • “secure a Workhuman integration”
  • “/workhuman-security-basics”

Requirements

  • Compatibility (from SKILL.md): Designed for Claude Code; security, privacy, SSO, privilege, retention, and integration changes require accountable owner approval
  • Pre-approved tools (allowed-tools): Read, Glob, Grep, WebFetch, Write, Edit

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. Diagram identity, worker, recognition, award, redemption, payment-adjacent, reporting, and integration data flows.
  2. Classify fields and define purpose, authority, access, retention, residency, export, deletion, and incident ownership.
  3. Review SSO, lifecycle, privileges, groups, delegates, separation of duties, dormant access, and emergency access.
  4. Threat-model spoofing, cross-tenant access, unsafe messages, approval bypass, award manipulation, fraud, replay, and data exfiltration.
  5. Verify encryption, secret storage, egress allowlists, audit evidence, anomaly detection, and redacted observability at each…
  6. Reconcile program spend and sensitive administrative actions with independent evidence and named approvers.
  7. Test access removal, credential rotation, rejected inputs, duplicate writes, incident containment, and recovery with synthetic fixtures.
  8. Present gaps with owner, severity, compensating control, due date, verification, and rollback before changing production.

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Glob
    • Grep
    • WebFetch
    • Write
    • Edit

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • workhuman.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code; security, privacy, SSO, privilege, retention, and integration changes require accountable owner approval

    From compatibility in the SKILL.md frontmatter.

Context cost

Workhuman Security Basics loads about 1.1k tokens when it runs. Until then it costs about 64 tokens; SKILL.md has 400 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~64
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 400 words, ~1,077 tokens.

Download SKILL.mdSave it as .claude/skills/workhuman-security-basics/SKILL.md (or your agent's skills folder).
name
workhuman-security-basics
description
Define shared-responsibility security controls for Workhuman identity, workforce data, recognition, awards, Store, and integrations. Use when reviewing threats or hardening controls. Trigger with "secure a Workhuman integration".
allowed-tools
Read, Glob, Grep, WebFetch, Write, Edit
compatibility
Designed for Claude Code; security, privacy, SSO, privilege, retention, and integration changes require accountable owner approval
argument-hint
[tenant-or-workflow] [data-classification]
version
1.4.0
author
Jeremy Longshore <jeremy@intentsolutions.io>
license
MIT
tags
saas, workhuman, security, privacy, governance
model
inherit
effort
high

Workhuman Security and Privacy Baseline

Overview

Map customer and Workhuman responsibilities and enforce least privilege, data minimization, financial integrity, and evidence-based incident controls.

Prerequisites

  • Tenant products, integrations, data flows, environments, owners, and current agreements
  • Workforce-data classification, retention, residency, legal, and incident requirements
  • Identity, HCM, payroll, recognition, security, privacy, and vendor contacts

Tool Discipline

Use Read, Glob, and Grep to inspect configurations and flows, WebFetch to verify current first-party commitments, and Write or Edit for threat models, control matrices, and redacted evidence.

Current Contract

Workhuman publicly states support for SSO, fraud detection, granular user privileges and grouping, encryption and monitoring practices, GDPR and CCPA compliance, ISO 27001:2022 and ISO 27701:2019 certification, and defined PCI scope. Confirm scope and customer obligations in current agreements rather than treating marketing statements as the entire control contract.

Authentication

Separate human SSO, administrator roles, managed connectors, and API principals. Enforce least privilege, tenant isolation, rotation, revocation, break-glass controls, and non-exportable secrets.

Instructions

  1. Diagram identity, worker, recognition, award, redemption, payment-adjacent, reporting, and integration data flows.
  2. Classify fields and define purpose, authority, access, retention, residency, export, deletion, and incident ownership.
  3. Review SSO, lifecycle, privileges, groups, delegates, separation of duties, dormant access, and emergency access.
  4. Threat-model spoofing, cross-tenant access, unsafe messages, approval bypass, award manipulation, fraud, replay, and data exfiltration.
  5. Verify encryption, secret storage, egress allowlists, audit evidence, anomaly detection, and redacted observability at each customer-controlled boundary.
  6. Reconcile program spend and sensitive administrative actions with independent evidence and named approvers.
  7. Test access removal, credential rotation, rejected inputs, duplicate writes, incident containment, and recovery with synthetic fixtures.
  8. Present gaps with owner, severity, compensating control, due date, verification, and rollback before changing production.
Show full SKILL.md (120 more words)Show less

Approval Boundaries

Do not alter SSO, roles, groups, retention, exports, fraud controls, integrations, or financial workflows without security, privacy, and business-owner approval.

Output

Return the responsibility and data-flow maps, access review, threat model, control evidence, gaps, approved changes, test receipts, and residual risks.

Error Handling

ConditionResponse
Agreement scope is unavailableMark controls unverified and request the current customer documents.
Cross-tenant or financial-integrity risk appearsStop affected processing and activate the approved incident path.
Required data has no owner or retention ruleBlock the flow until governance is assigned.

Example

A redacted completion receipt might look like this:

text
tenant=customer-prod; flows=7; principals=4; high-gaps=0; rotation=tested; spend-reconciliation=exact; residual-risk=accepted

Resources

Next Steps

Schedule access, data-flow, contract-scope, and recovery reviews on the customer's governance cadence.

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/.curated/workhuman-security-basics of jeremylongshore/tons-of-skills-marketplace.

Open the folder on GitHubat commit cfae287

Compare with similar skills

Workhuman Security Basics next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Workhuman Security Basics compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Workhuman Security Basics this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.1kAutomated safety check: PassMIT
Paper to Chinese Patent DrafterYuan1z0825/nature-skills47k1 repos~1.1kAutomated safety check: PassApache-2.0
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
Contract Reviewevolsb/claude-legal-skill4641 repos~3.6kAutomated safety check: PassMIT
Legal Clinic Client Intakeanthropics/claude-for-legal9.6k3 repos~3.2kAutomated safety check: PassApache-2.0
Paper To Cn Patentsnipp-zha/Paper-to-patent-Skill1071 repos~959Automated safety check: PassNone

Similar skills

  • Paper to Chinese Patent Drafter

    Yuan1z0825/nature-skills

    Drafts Chinese invention patent applications and technical disclosures from research papers or inventor materials, tying each claim feature to source evidence.

    47k GitHub starsUsed in 1 repo~1.1k tokens
    Legal & ComplianceAuto-check passed
  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Contract Review

    evolsb/claude-legal-skill

    Review legal contracts, NDAs, employment agreements, SaaS terms, and M&A documents.

    464 GitHub starsUsed in 1 repo~3.6k tokens
    Legal & ComplianceAuto-check passed
  • Legal Clinic Client Intake

    anthropics/claude-for-legal

    Official

    Structures a legal clinic client intake interview and produces a case summary with cross-area issue spotting, conflict flags and triage classification.

    9.6k GitHub starsUsed in 3 repos~3.2k tokens
    Legal & ComplianceAuto-check passed
  • Paper To Cn Patent

    snipp-zha/Paper-to-patent-Skill

    Convert scientific papers, theses, technical reports, source code, figures, or research manuscripts into evidence-grounded Chinese invention patent drafts.

    107 GitHub starsUsed in 1 repo~959 tokens
    Legal & ComplianceAuto-check passed
  • Employment Contract Templates

    ynulihao/AgentSkillOS

    Create employment contracts, offer letters, and HR policy documents following legal best practices.

    618 GitHub starsUsed in 12 repos~4.1k tokens
    Legal & ComplianceAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Questions about Workhuman Security Basics

What does Workhuman Security Basics do?

Define shared-responsibility security controls for Workhuman identity, workforce data, recognition, awards, Store, and integrations. Workhuman Security Basics is an agent skill from jeremylongshore/tons-of-skills-marketplace. Define shared-responsibility security controls for Workhuman identity, workforce data, recognition, awards, Store, and integrations.

When should I use Workhuman Security Basics?

Workhuman Security Basics fits situations like: reviewing threats; hardening controls; with secure a Workhuman integration.

How do I install Workhuman Security Basics in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill workhuman-security-basics -a claude-code`. Or copy the skill folder (skills/.curated/workhuman-security-basics in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/workhuman-security-basics in your project. Claude Code loads it when a task matches its description.

How do I install Workhuman Security Basics in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill workhuman-security-basics -a codex`. Or copy the skill folder (skills/.curated/workhuman-security-basics in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/workhuman-security-basics in your project. Codex loads it when a task matches its description.

Can I use Workhuman Security Basics in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill workhuman-security-basics -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/workhuman-security-basics, .gemini/skills/workhuman-security-basics, .github/skills/workhuman-security-basics and .opencode/skills/workhuman-security-basics in your project.

What does Workhuman Security Basics need to run?

SKILL.md names no scripts, command-line tools or credentials: Workhuman Security Basics is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Glob, Grep, WebFetch, Write, Edit. Compatibility (from SKILL.md): Designed for Claude Code; security, privacy, SSO, privilege, retention, and integration changes require accountable owner approval.

Does Workhuman Security Basics access the network?

SKILL.md names 1 domain. As links in the text: workhuman.com. This is read from the text; nothing was executed.

Is Workhuman Security Basics safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Workhuman Security Basics use?

Workhuman Security Basics is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Workhuman Security Basics use?

About 1.1k tokens (SKILL.md is roughly 4.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Workhuman Security Basics?

Skills that share tags, products or a category with Workhuman Security Basics: Paper to Chinese Patent Drafter (Yuan1z0825/nature-skills, 47k stars), C15t (c15t/c15t, 1.9k stars), Contract Review (evolsb/claude-legal-skill, 464 stars) and Legal Clinic Client Intake (anthropics/claude-for-legal, 9.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Workhuman Security Basics?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.