Agent skill

Mcaf Security Baseline

by managedcode in managedcode/Storage

Apply baseline engineering security guidance: secrets handling, secure defaults, threat modelling references, and review checkpoints for auth, data flow, pipelines, and external integrations.

MITAuto-check passedAgent Workflows

Install Mcaf Security Baseline

skills CLI
$ npx skills add managedcode/Storage --skill mcaf-security-baseline -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install managedcode/Storage mcaf-security-baseline --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/managedcode/Storage.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/mcaf-security-baseline .claude/skills/mcaf-security-baseline && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
mcaf-security-baseline
GitHub stars
138
Token cost
~970 tokens
SKILL.md length
470 words
Files
4 (incl. references)
Skills in repo
41
Repo updated
First seen
Licence
MIT

At a glance

Apply baseline engineering security guidance: secrets handling, secure defaults, threat modelling references, and review checkpoints for auth, data flow, pipelines, and external integrations.

  • Works in 3 steps: Read the nearest AGENTS.md and confirm… → Run this skill's Workflow through the… → Return the Required Result Format with…
  • A change has security impact but does not require a full standalone AppSec engagement
  • SKILL.md covers Trigger On, Value, Do Not Use For and Inputs, plus 7 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Mcaf Security Baseline is an agent skill from managedcode/Storage. Apply baseline engineering security guidance: secrets handling, secure defaults, threat modelling references, and review checkpoints for auth, data flow, pipelines, and external integrations. Use when a change has security impact but does not require a full standalone AppSec engagement.

Its SKILL.md is about 970 tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/rules-of-engagement.md`, `references/security.md` and `references/threat-modelling.md`). Compatibility notes: Requires repository access; may update security docs, ADRs, and verification steps.

It sits in Agent Workflows. The repository describes itself as: Storage library provides a universal interface for accessing and manipulating data in different cloud blob storage providers. The licence is MIT.

When your agent uses it

  • A change has security impact but does not require a full standalone AppSec engagement

Example prompts

  • “/mcaf-security-baseline”

Requirements

  • Compatibility (from SKILL.md): Requires repository access; may update security docs, ADRs, and verification steps.

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Read the nearest AGENTS.md and confirm scope and constraints.
  2. Run this skill's Workflow through the Ralph Loop until outcomes are acceptable.
  3. Return the Required Result Format with concrete artifacts and verification evidence.

What it can do on your machine

Read from SKILL.md and the folder at commit 5d32121. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires repository access; may update security docs, ADRs, and verification steps.

    From compatibility in the SKILL.md frontmatter.

Context cost

Mcaf Security Baseline loads about 970 tokens when it runs, and up to ~1.7k if it reads all its reference files. Until then it costs about 78 tokens; SKILL.md has 470 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~78
When it runs · the whole SKILL.md, loaded when a task matches
~970
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from managedcode/Storage at commit 5d32121, republished under its MIT licence (© managedcode). 470 words, ~970 tokens.

Download SKILL.mdSave it as .claude/skills/mcaf-security-baseline/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
mcaf-security-baseline
description
Apply baseline engineering security guidance: secrets handling, secure defaults, threat modelling references, and review checkpoints for auth, data flow, pipelines, and external integrations. Use when a change has security impact but does not require a full standalone AppSec engagement.
compatibility
Requires repository access; may update security docs, ADRs, and verification steps.

MCAF: Security Baseline

Trigger On

  • a change has security impact but does not need a full separate AppSec exercise
  • the work touches auth, secrets, trust boundaries, data flow, or pipeline permissions
  • the team needs secure-default guidance before implementing

Value

  • produce a concrete project delta: code, docs, config, tests, CI, or review artifact
  • reduce ambiguity through explicit planning, verification, and final validation skills
  • leave reusable project context so future tasks are faster and safer

Do Not Use For

  • a full standalone threat-modeling engagement
  • generic code review with no security surface

Inputs

  • the changed boundary, data flow, or integration
  • auth, secret, and permission model for the affected path
  • current security docs, ADRs, or CI rules

Quick Start

  1. Read the nearest AGENTS.md and confirm scope and constraints.
  2. Run this skill's Workflow through the Ralph Loop until outcomes are acceptable.
  3. Return the Required Result Format with concrete artifacts and verification evidence.

Workflow

  1. Identify the security surface:
    • authn and authz
    • secrets
    • external inputs
    • storage and transport
    • pipeline permissions
  2. Apply secure defaults and least privilege before adding behaviour.
  3. If the change introduces a trust boundary, update or add an ADR and link the reasoning.
  4. Pull the relevant security references, not the whole set.

Deliver

  • security-aware design or implementation guidance
  • updated security checkpoints in docs, ADRs, or CI
  • the right threat-model references for the impacted area

Validate

  • secrets are handled explicitly
  • authn and authz assumptions are visible
  • new trust boundaries are documented
  • the change does not smuggle insecure defaults into the repo
Show full SKILL.md (218 more words)Show less

Ralph Loop

Use the Ralph Loop for every task, including docs, architecture, testing, and tooling work.

  1. Plan first (mandatory):
    • analyze current state
    • define target outcome, constraints, and risks
    • write a detailed execution plan
    • list final validation skills to run at the end, with order and reason
  2. Execute one planned step and produce a concrete delta.
  3. Review the result and capture findings with actionable next fixes.
  4. Apply fixes in small batches and rerun the relevant checks or review steps.
  5. Update the plan after each iteration.
  6. Repeat until outcomes are acceptable or only explicit exceptions remain.
  7. If a dependency is missing, bootstrap it or return status: not_applicable with explicit reason and fallback path.
Required Result Format
  • status: complete | clean | improved | configured | not_applicable | blocked
  • plan: concise plan and current iteration step
  • actions_taken: concrete changes made
  • validation_skills: final skills run, or skipped with reasons
  • verification: commands, checks, or review evidence summary
  • remaining: top unresolved items or none

For setup-only requests with no execution, return status: configured and exact next commands.

Load References

  • read references/security.md first
  • open references/rules-of-engagement.md or references/threat-modelling.md only when they match the task

Example Requests

  • "Review the security baseline for this new OAuth flow."
  • "We are adding a webhook. What baseline security work is required?"
  • "Tighten secrets and pipeline permissions for this repo."

© managedcode, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in .codex/skills/mcaf-security-baseline of managedcode/Storage.

  • SKILL.md
  • references/rules-of-engagement.md
  • references/security.md
  • references/threat-modelling.md

Open the folder on GitHubat commit 5d32121

Compare with similar skills

Mcaf Security Baseline next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Mcaf Security Baseline compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Mcaf Security Baseline this skillmanagedcode/Storage138—~970Automated safety check: PassMIT
MCP Server Builderanthropics/skills180k62 repos~2.3kAutomated safety check: PassApache-2.0
MCP Server BuildershareAI-lab/learn-claude-code78k5 repos~1.2kAutomated safety check: PassMIT
Brainstormingxpinjection/test-driven-spring-boot11254 repos~2.6kAutomated safety check: PassMIT
MCP Integration for Pluginsanthropics/claude-plugins-official37k11 repos~3.1kAutomated safety check: PassApache-2.0
MCP Server Builder with mcp-usemcp-use/mcp-use11k—~923Automated safety check: PassApache-2.0

Similar skills

  • MCP Server Builder

    anthropics/skills

    Official

    Guides the design and implementation of Model Context Protocol servers in TypeScript or Python, from tool naming and error messages to evaluation.

    180k GitHub starsUsed in 62 repos~2.3k tokens
    Agent WorkflowsAuto-check passed
  • MCP Server Builder

    shareAI-lab/learn-claude-code

    Walks through building MCP servers in Python or TypeScript that expose tools, resources and prompts to Claude, with templates, registration and testing.

    78k GitHub starsUsed in 5 repos~1.2k tokens
    Agent WorkflowsAuto-check passed
  • Brainstorming

    xpinjection/test-driven-spring-boot

    You MUST use this before any creative work - creating features, building components, adding functionality, or modifying behavior.

    112 GitHub starsUsed in 54 repos~2.6k tokens
    Agent WorkflowsAuto-check passed
  • MCP Integration for Plugins

    anthropics/claude-plugins-official

    Official

    Explains how to bundle Model Context Protocol servers in a Claude Code plugin, covering config files, stdio, SSE, HTTP and WebSocket server types, and authentication.

    37k GitHub starsUsed in 11 repos~3.1k tokens
    Agent WorkflowsAuto-check passed
  • Builds, modifies, debugs, migrates and verifies TypeScript MCP servers and MCP Apps with the mcp-use framework, treating the installed package's types as the source of truth.

    11k GitHub stars~923 tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Agents SDK

    cloudflare/skills

    Official

    Build, debug, or review Cloudflare Agents SDK applications using the agents package.

    3k GitHub starsUsed in 2 repos~3k tokens
    Agent WorkflowsAuto-check passed

More from managedcode/Storage

All 41 skills in this repo
  • Mcaf Adr Writing

    managedcode/Storage

    Create or update an ADR under docs/ADR/ for architectural decisions, dependency changes, data-model changes, or cross-cutting policy shifts.

    138 GitHub stars~951 tokensUpdated today
    Auto-check passed
  • Mcaf Agile Delivery

    managedcode/Storage

    Shape delivery workflow around backlog quality, roles, ceremonies, and engineering feedback.

    138 GitHub stars~883 tokensUpdated today
    Auto-check passed
  • Mcaf Architecture Overview

    managedcode/Storage

    Create or update docs/Architecture.md as the global architecture map for a solution.

    138 GitHub stars~950 tokensUpdated today
    Auto-check passed
  • Mcaf CI CD

    managedcode/Storage

    Design or refine CI/CD workflows, quality gates, release flow, and safe AI-assisted pipeline authoring.

    138 GitHub stars~981 tokensUpdated today
    Auto-check passed
  • Mcaf Code Review

    managedcode/Storage

    Prepare for, perform, or tighten code review workflow: PR scope, review checklist, reviewer expectations, and merge hygiene.

    138 GitHub stars~957 tokensUpdated today
    Auto-check passed
  • Mcaf Devex

    managedcode/Storage

    Improve developer experience for multi-component solutions: onboarding, F5 contract, cross-platform tasks, local inner loop, and reproducible setup.

    138 GitHub stars~911 tokensUpdated today
    Auto-check passed

Questions about Mcaf Security Baseline

What does Mcaf Security Baseline do?

Apply baseline engineering security guidance: secrets handling, secure defaults, threat modelling references, and review checkpoints for auth, data flow, pipelines, and external integrations. Mcaf Security Baseline is an agent skill from managedcode/Storage. Apply baseline engineering security guidance: secrets handling, secure defaults, threat modelling references, and review checkpoints for auth, data flow, pipelines, and external integrations.

When should I use Mcaf Security Baseline?

Mcaf Security Baseline fits situations like: A change has security impact but does not require a full standalone AppSec engagement.

How do I install Mcaf Security Baseline in Claude Code?

Run `npx skills add managedcode/Storage --skill mcaf-security-baseline -a claude-code`. Or copy the skill folder (.codex/skills/mcaf-security-baseline in managedcode/Storage) into .claude/skills/mcaf-security-baseline in your project. Claude Code loads it when a task matches its description.

How do I install Mcaf Security Baseline in Codex?

Run `npx skills add managedcode/Storage --skill mcaf-security-baseline -a codex`. Or copy the skill folder (.codex/skills/mcaf-security-baseline in managedcode/Storage) into .agents/skills/mcaf-security-baseline in your project. Codex loads it when a task matches its description.

Can I use Mcaf Security Baseline in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add managedcode/Storage --skill mcaf-security-baseline -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/mcaf-security-baseline, .gemini/skills/mcaf-security-baseline, .github/skills/mcaf-security-baseline and .opencode/skills/mcaf-security-baseline in your project.

What does Mcaf Security Baseline need to run?

SKILL.md names no scripts, command-line tools or credentials: Mcaf Security Baseline is instructions for the agent only. Compatibility (from SKILL.md): Requires repository access; may update security docs, ADRs, and verification steps..

Does Mcaf Security Baseline access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Mcaf Security Baseline safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Mcaf Security Baseline use?

Mcaf Security Baseline is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Mcaf Security Baseline use?

About 970 tokens (SKILL.md is roughly 3.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 770 tokens, read only when the agent opens those files.

What are the alternatives to Mcaf Security Baseline?

Skills that share tags, products or a category with Mcaf Security Baseline: MCP Server Builder (anthropics/skills, 180k stars), MCP Server Builder (shareAI-lab/learn-claude-code, 78k stars), Brainstorming (xpinjection/test-driven-spring-boot, 112 stars) and MCP Integration for Plugins (anthropics/claude-plugins-official, 37k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Mcaf Security Baseline?

managedcode (a GitHub organization) maintains it in managedcode/Storage, which has 138 GitHub stars. The repository holds 41 skills in this directory. The repository was last updated on October 7, 2026.

Source: managedcode/Storage on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.