Notion Pm
borghei/Claude-Skills
Notion expert for product management workflows. An agent skill from borghei/Claude-Skills.
Generate, scaffold, or refactor code so it embodies FIASSE v1.0.4 SSEM qualities by default — 10 attributes, Transparency and Least-Astonishment principles, ASVS-aligned controls, defensive boundary…
$ npx skills add OWASP/secure-agent-playbook --skill securability-engineering -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install OWASP/secure-agent-playbook securability-engineering --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/OWASP/secure-agent-playbook.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/code-security-skills/skills/securability-engineering .claude/skills/securability-engineering && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "securability-engineering" agent skill from https://github.com/OWASP/secure-agent-playbook/tree/main/plugins/code-security-skills/skills/securability-engineering into .claude/skills/securability-engineering/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "securability-engineering", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/OWASP/secure-agent-playbook/tree/main/plugins/code-security-skills/skills/securability-engineeringType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add OWASP/secure-agent-playbook --skill securability-engineering -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install OWASP/secure-agent-playbook securability-engineering --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OWASP/secure-agent-playbook.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/code-security-skills/skills/securability-engineering .agents/skills/securability-engineering && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "securability-engineering" agent skill from https://github.com/OWASP/secure-agent-playbook/tree/main/plugins/code-security-skills/skills/securability-engineering into .agents/skills/securability-engineering/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "securability-engineering", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add OWASP/secure-agent-playbook --skill securability-engineering -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install OWASP/secure-agent-playbook securability-engineering --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OWASP/secure-agent-playbook.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/code-security-skills/skills/securability-engineering .cursor/skills/securability-engineering && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "securability-engineering" agent skill from https://github.com/OWASP/secure-agent-playbook/tree/main/plugins/code-security-skills/skills/securability-engineering into .cursor/skills/securability-engineering/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "securability-engineering", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/OWASP/secure-agent-playbook.git --path plugins/code-security-skills/skills/securability-engineering--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add OWASP/secure-agent-playbook --skill securability-engineering -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install OWASP/secure-agent-playbook securability-engineering --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OWASP/secure-agent-playbook.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/code-security-skills/skills/securability-engineering .gemini/skills/securability-engineering && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "securability-engineering" agent skill from https://github.com/OWASP/secure-agent-playbook/tree/main/plugins/code-security-skills/skills/securability-engineering into .gemini/skills/securability-engineering/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "securability-engineering", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install OWASP/secure-agent-playbook securability-engineeringInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add OWASP/secure-agent-playbook --skill securability-engineering -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/OWASP/secure-agent-playbook.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/code-security-skills/skills/securability-engineering .github/skills/securability-engineering && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "securability-engineering" agent skill from https://github.com/OWASP/secure-agent-playbook/tree/main/plugins/code-security-skills/skills/securability-engineering into .github/skills/securability-engineering/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "securability-engineering", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add OWASP/secure-agent-playbook --skill securability-engineering -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install OWASP/secure-agent-playbook securability-engineering --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OWASP/secure-agent-playbook.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/code-security-skills/skills/securability-engineering .opencode/skills/securability-engineering && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "securability-engineering" agent skill from https://github.com/OWASP/secure-agent-playbook/tree/main/plugins/code-security-skills/skills/securability-engineering into .opencode/skills/securability-engineering/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "securability-engineering", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
securability-engineeringGenerate, scaffold, or refactor code so it embodies FIASSE v1.0.4 SSEM qualities by default — 10 attributes, Transparency and Least-Astonishment principles, ASVS-aligned controls, defensive boundary…
Securability Engineering is an agent skill from OWASP/secure-agent-playbook. Generate, scaffold, or refactor code so it embodies FIASSE v1.0.4 SSEM qualities by default — 10 attributes, Transparency and Least-Astonishment principles, ASVS-aligned controls, defensive boundary handling. Trigger on "secure/securable/FIASSE-compliant code", "harden", "secure-by-default", "audit-ready", or security-sensitive components (auth, file upload, password reset, input validation, API endpoints, queries) — even when those words are not explicit. For requirements use prd-securability-enhancement; for…
Its SKILL.md is about 5.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file.
It sits in Product & Project Management, covering PRD writing, File uploads and storage and REST APIs. The repository describes itself as: OWASP Secure Agent Playbook Project. The licence is CC-BY-4.0.
9 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 1b5fd4c. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are python and markdown).
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Securability Engineering loads about 5.8k tokens when it runs. Until then it costs about 170 tokens; SKILL.md has 2,439 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from OWASP/secure-agent-playbook at commit 1b5fd4c, republished under its CC-BY-4.0 licence (© OWASP). 2,439 words, ~5,836 tokens.
.claude/skills/securability-engineering/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.This skill augments the built-in code generation capability by applying FIASSE v1.0.4 SSEM principles as engineering constraints. It does not perform full SSEM scoring (use securability-engineering-review for that).
The end-to-end PRD-enhance → generate → review → enhance → report loop is opt-in, not the default. See "Full Loop Mode" below.
Reference data: data/fiasse/ (especially S2.1–S2.6 foundational principles, S3.2.1–S3.2.3 SSEM attributes including S3.2.1.4 Observability, S2.5 Transparency, S4.3 Boundary Control, S4.4 Resilient Coding, S4.4.1 Canonical Input Handling, S4.6 Dependency Stewardship) and data/asvs/ for feature-level requirements.
Trigger this skill when the user asks to:
Watch for adjacent phrasings: "make this safe", "harden this endpoint", "I'm exposing this to the internet, can you...", "write the production version of...", "audit-ready", "production-grade".
Produce securable code from the user's request directly, applying SSEM constraints. Most invocations land here. The output is code + a Securability Notes block.
Run the full PRD-enhance → generate → review → enhance → report workflow. Activate only when the user:
--full-loop flag or argumentOtherwise stay in Default Mode. Do not invent a PRD for a small one-shot generation request.
When Full Loop Mode is active, follow plays/securable-generation.md. When Default Mode is active, follow this file alone.
Before generating any code, apply these FIASSE v1.0.4 principles:
Every code generation output must satisfy these ten attributes. Read data/fiasse/ sections for definitions when context is needed.
| Attribute | Enforcement |
|---|---|
| Analyzability (FIASSE v1.0.4 S3.2.1.1) | Methods ≤ 30 LoC. Cyclomatic complexity < 10. Clear, descriptive naming. No dead code. Comments only at trust boundaries and complex logic, explaining why — not what. |
| Modifiability (FIASSE v1.0.4 S3.2.1.2) | Loose coupling via interfaces / dependency injection. No static mutable state. Security-sensitive logic (auth, crypto, validation) centralized in dedicated modules, not scattered across call sites. Configuration externalized. |
| Testability (FIASSE v1.0.4 S3.2.1.3) | All public interfaces testable without modifying code under test. Dependencies injectable / mockable. Security controls isolated for dedicated test suites. |
| Observability (FIASSE v1.0.4 S3.2.1.4) | Code-level instrumentation, not external tooling alone. Structured logs with sufficient context (who/what/where/when/outcome) at trust boundaries and security-sensitive operations. Health and performance metrics exposed through a standardized API. Failure paths produce observable signals; no silent exception swallowing. UI/operator feedback surfaces meaningful state without leaking internals. |
| Attribute | Enforcement |
|---|---|
| Confidentiality (FIASSE v1.0.4 S3.2.2.1) | Sensitive data classified at the type level. Least-privilege data access. No secrets in code, logs, or error messages. Encryption at rest and in transit where applicable. Data minimization. |
| Accountability (FIASSE v1.0.4 S3.2.2.2) | Security-sensitive actions logged with structured data (who, what, where, when). Audit trails append-only. Auth events (login, logout, failure) and authz decisions (grant, deny) recorded. No sensitive data in logs. |
| Authenticity (FIASSE v1.0.4 S3.2.2.3) | Use established authentication mechanisms. Verify token/session integrity (signed JWTs with pinned algorithm, secure cookies). Mutually authenticate service-to-service calls. Support non-repudiation. |
| Attribute | Enforcement |
|---|---|
| Availability (FIASSE v1.0.4 S3.2.3.1) | Enforce resource limits (memory, connections, file handles). Configure timeouts for all external calls. Rate-limit where appropriate. Thread-safe design for concurrent code. Graceful degradation for non-critical failures. |
| Integrity (FIASSE v1.0.4 S3.2.3.2) | Validate input at every trust boundary: canonicalize → sanitize → validate (FIASSE v1.0.4 S4.4.1). Output-encode when crossing trust boundaries. Use parameterized queries exclusively. Apply Derived Integrity (FIASSE v1.0.4 S4.4.1.2) and Request Surface Minimization (FIASSE v1.0.4 S4.4.1.1). |
| Resilience (FIASSE v1.0.4 S3.2.3.3) | Defensive coding: anticipate out-of-bounds input. Specific exception handling — no bare catch-all. Sandbox null checks to input/DB boundaries. Use immutable data structures in concurrent code. Deterministic disposal patterns (with, using, RAII). Graceful and secure failure: error messages don't leak internals. |
Apply the Boundary Control Principle (the "turtle analogy"): hard shell at trust boundaries, flexible interior.
Boundary input is hostile until proven otherwise — and "hostile" includes well-meaning but unusual, not just attacker-crafted. Real protocols and formats have edge cases that naive parsers fail on. Before writing any boundary-parsing code, think through these classes of variation explicitly:
Bearer, bearer, BEARER per RFC 6750/7235); leading/trailing whitespace; multiple values; comma-separated lists; non-ASCII; missing entirely./a/./b → /a/b), traversal (..), trailing slash, mixed-case schemes, IDN/punycode, repeated query keys.CON, PRN on Windows), traversal segments.Infinity/NaN, locale-specific separators, "yes"/"true"/"1"/"on" boolean variants.; charset=utf-8), spoofed declared type vs sniffed type."123" vs 123).Bearer already stripped or not.Don't enumerate all of these in code — pick the ones that matter for this boundary and handle them deliberately. The default for any RFC-defined token is "follow the RFC, don't reject the spec-compliant variant just because your prototype only saw one shape."
data/asvs/README.md and the relevant data/asvs/V*.md chapters to identify the security requirements applying to the feature being generated.data/fiasse/S3.2.1.md–S3.2.3.md for umbrella definitions.The code itself is the primary deliverable. After the code, append a short Securability Notes block:
## Securability Notes
- **SSEM attributes enforced**: [the 2–4 that actually shape this code, named briefly]
- **ASVS references**: [V-chapter.section IDs that apply]
- **Trust boundaries**: [where input is canonicalized/validated]
- **Dependencies**: [package@version — only when something non-trivial was introduced]
- **Trade-offs**: [decisions a reviewer needs to know — e.g., "in-process rate limit; switch to shared store for multi-instance"]Skip bullets that have nothing material to say. For tiny edits with no boundary crossing, a single sentence is enough. The point of this block is to make review faster, not to perform thoroughness.
User request: "Write a Python FastAPI endpoint that lets a logged-in user fetch one of their own orders by ID."
Sloppy default (what to avoid):
@app.get("/orders/{order_id}")
def get_order(order_id: str, current_user=Depends(get_user)):
order = db.query("SELECT * FROM orders WHERE id = '" + order_id + "'")
return orderIssues: SQL injection (string concatenation), missing ownership check (any user can read any order — IDOR), broad return shape leaks fields, no logging, no input validation, no error handling.
Securable version:
from fastapi import APIRouter, Depends, HTTPException
from pydantic import BaseModel
from uuid import UUID
import structlog
router = APIRouter()
log = structlog.get_logger()
class OrderView(BaseModel):
id: UUID
placed_at: str
status: str
total_cents: int
@router.get("/orders/{order_id}", response_model=OrderView)
def get_order(
order_id: UUID, # canonicalized: must parse as UUID or 422
current_user = Depends(get_authenticated_user), # auth at the boundary
orders = Depends(get_orders_repo), # injectable for tests
):
order = orders.find_owned_by(order_id, current_user.id) # ownership enforced server-side
if order is None:
log.info("order_lookup.denied",
user_id=current_user.id, order_id=str(order_id), reason="not_found_or_not_owned")
raise HTTPException(status_code=404, detail="Order not found")
log.info("order_lookup.granted",
user_id=current_user.id, order_id=str(order_id))
return OrderView.model_validate(order)What changed and why:
order_id: UUID canonicalizes input at the boundary (Integrity, FIASSE v1.0.4 S4.4.1).find_owned_by(order_id, user_id) enforces ownership server-side — current_user.id is server-owned state, never trusted from the client (Derived Integrity, FIASSE v1.0.4 S4.4.1.2).OrderView projection limits the response to expected fields (Confidentiality; Request Surface Minimization, FIASSE v1.0.4 S4.4.1.1).Depends(get_orders_repo) is injectable, so tests can run without a real DB (Testability, Modifiability).These are the patterns to not emit during generation. Each row pairs the bad shape with the principle it would violate, so when you find yourself about to write one, you know what's going wrong and what the correct shape looks like.
| Pattern to avoid emitting | Principle / attribute violated | Tag | Correct shape instead |
|---|---|---|---|
| String-built SQL / shell / format strings touching user input | Integrity — input handling at boundary (FIASSE v1.0.4 S4.4.1, S4.3) | "Trust boundary input handling" | Parameterized query / subprocess arg list / format with placeholders |
Trusting req.body.user_id, X-Tenant-ID, JWT claims for authorization decisions | Integrity — Derived Integrity (FIASSE v1.0.4 S4.4.1.2) | "Derived Integrity violation" | Look up user/tenant from authenticated session; never client-asserted |
Spreading req.body / **request.json directly into ORM update | Integrity — Request Surface Minimization (FIASSE v1.0.4 S4.4.1.1) | "Mass assignment" | Explicit allow-list of named fields → typed DTO → mapped update |
os.path.join(base, user_input) / template path concatenation | Integrity — boundary canonicalization (FIASSE v1.0.4 S4.4.1) | "Path canonicalization gap" | Resolve absolute path, assert it's under base, reject otherwise |
jwt.decode(token) with default algorithms / no aud / no iss | Authenticity (FIASSE v1.0.4 S3.2.2.3) | "Token verification under-specified" | jwt.decode(token, key, algorithms=['RS256'], audience=..., issuer=...) |
print(...) / console.log(...) / fmt.Println(...) for security events | Accountability + Observability (FIASSE v1.0.4 S2.5, S3.2.1.4) | "Unstructured audit trail" | Structured logger emitting {event, actor, target, outcome, request_id} |
try: ... except: pass / silent failure paths | Observability (FIASSE v1.0.4 S3.2.1.4); Resilience (FIASSE v1.0.4 S3.2.3.3) | "Silent failure" | Specific exception types; log with context; re-raise or return typed error |
Bare except: / catch (e) returning raw exception text | Resilience; Confidentiality (FIASSE v1.0.4 S3.2.3.3, S3.2.2.1) | "Specific exception handling missing" | Named exception types, generic public message, internal log with detail |
| Module-level globals (DB connection, app, config) created at import | Modifiability + Testability (FIASSE v1.0.4 S3.2.1.2, S3.2.1.3) | "Import-time side effects" | Factory function / DI container / fixture-injected dependencies |
request.body.read() / ioutil.ReadAll(r.Body) with no size cap | Availability + Resilience (FIASSE v1.0.4 S3.2.3.1, S3.2.3.3) | "Unbounded resource consumption" | Bounded reader; explicit max_size; 413 on overflow |
password == request.password / non-constant-time secret comparison | Authenticity; Confidentiality | "Timing-side-channel comparison" | hmac.compare_digest / language equivalent |
| Hardcoded secrets, connection strings, or API keys | Confidentiality (FIASSE v1.0.4 S3.2.2.1) | "Secret in code" | Env var / secret manager; pass via injected config |
any / interface{} / dynamic on the trust-boundary surface | Analyzability + Integrity | "Trust-boundary type erasure" | Concrete typed DTO / Pydantic model / typed struct |
setTimeout / time.sleep as a substitute for actual rate limiting | Availability (FIASSE v1.0.4 S3.2.3.1) | "Sleep-based throttling" | Real rate limiter (token bucket / fixed window) keyed by actor |
External call without timeout (requests.get(url), http.Client{}) | Availability + Resilience | "Unbounded external call" | Explicit timeout= / configured Client with timeouts |
| Logging the full request body / response body / token by default | Confidentiality + Accountability (sensitive data in audit) | "PII in audit log" | Log structured event with IDs only; redact body and credential fields |
If you catch yourself emitting one of these, stop and rewrite.
Maintainability:
Trustworthiness:
ASVS feature requirements:
Reliability:
Dependency hygiene:
Transparency:
Anti-patterns avoided:
Output format:
try/except.data/asvs/README.md — ASVS chapter indexdata/asvs/V*.md — ASVS 5.0 feature requirements by chapterdata/fiasse/S2.1.md–S2.6.md — Foundational Principles (incl. Transparency S2.5 and Least Astonishment S2.6)data/fiasse/S3.2.1.md–S3.2.3.md — SSEM attribute umbrellas (Maintainability, Trustworthiness, Reliability)data/fiasse/S3.2.1.4.md — Observabilitydata/fiasse/S4.3.md — Boundary Control Principledata/fiasse/S4.4.md — Resilient Codingdata/fiasse/S4.4.1.md — Canonical Input Handlingdata/fiasse/S4.4.1.1.md — Request Surface Minimization Principledata/fiasse/S4.4.1.2.md — Derived Integrity Principledata/fiasse/S4.5.md / S4.6.md — Dependency Management and Stewardship© OWASP, CC-BY-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in plugins/code-security-skills/skills/securability-engineering of OWASP/secure-agent-playbook.
Open the folder on GitHubat commit 1b5fd4c
Securability Engineering next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Securability Engineering this skillOWASP/secure-agent-playbook | 186 | — | ~5.8k | Automated safety check: Pass | CC-BY-4.0 | |
| Notion Pmborghei/Claude-Skills | 874 | — | ~1.7k | Automated safety check: Pass | MIT | |
| App Spec Packagerinstructa/agent-skills | 139 | — | ~1.5k | Automated safety check: Pass | None | |
| Grilling Ideasopsmill/infrahub | 529 | — | ~3.8k | Automated safety check: Pass | Apache-2.0 | |
| Avoid Feature Creepwaynesutton/builder-skills | 404 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | |
| Cm Refactorkingxiaozhe/cm-workflow | 104 | — | ~2.7k | Automated safety check: Pass | MIT |
borghei/Claude-Skills
Notion expert for product management workflows. An agent skill from borghei/Claude-Skills.
instructa/agent-skills
A skill your agent uses when the user wants to turn an application, product, startup idea, SaaS, mobile app, web app, API, AI product, or internal tool into a production-ready Markdown specification…
opsmill/infrahub
Stress-tests a fuzzy or vague feature idea before any PRD, spec, or ticket is written.
waynesutton/builder-skills
Keeps a change scoped to what was asked. An agent skill from waynesutton/builder-skills.
kingxiaozhe/cm-workflow
用户明确要求“只整理结构,不改变行为”时使用。执行边界分流、行为判官、分批重构和独立审查;缺陷修复转交 cm-fix,新增或变化的业务行为转交 cm-prd。
Wirasm/prp
Autonomously owns one workstream from an issue, PRD, document, existing plan, or free-form request through planning, implementation, pull request, independent review, corrections, and green CI.
OWASP/secure-agent-playbook
Enhance PRDs, feature specs, user stories, or product briefs with explicit OWASP ASVS coverage and FIASSE v1.0.4 SSEM implementation guidance — before code is written.
OWASP/secure-agent-playbook
Score a codebase, file, or merge request against the FIASSE v1.0.4 SSEM model — 0-10 per attribute, equal-weighted pillars, evidence-backed strengths and weaknesses, prioritized recommendations…
OWASP/secure-agent-playbook
Audit AI agent configurations for security risks — excessive permissions, prompt injection surfaces, data exfiltration paths, and missing guardrails.
OWASP/secure-agent-playbook
Comprehensive AI security verification using OWASP AI Security Verification Standard (AISVS) framework.
OWASP/secure-agent-playbook
Comprehensive API security review against OWASP API Security Top 10 (2023).
OWASP/secure-agent-playbook
Security-focused code review mapped to OWASP Top 10 and ASVS.
Generate, scaffold, or refactor code so it embodies FIASSE v1.0.4 SSEM qualities by default — 10 attributes, Transparency and Least-Astonishment principles, ASVS-aligned controls, defensive boundary…. Securability Engineering is an agent skill from OWASP/secure-agent-playbook.4 SSEM qualities by default — 10 attributes, Transparency and Least-Astonishment principles, ASVS-aligned controls, defensive boundary handling.
Securability Engineering fits situations like: secure/securable/FIASSE-compliant code; secure-by-default; security-sensitive components (auth; input validation.
Run `npx skills add OWASP/secure-agent-playbook --skill securability-engineering -a claude-code`. Or copy the skill folder (plugins/code-security-skills/skills/securability-engineering in OWASP/secure-agent-playbook) into .claude/skills/securability-engineering in your project. Claude Code loads it when a task matches its description.
Run `npx skills add OWASP/secure-agent-playbook --skill securability-engineering -a codex`. Or copy the skill folder (plugins/code-security-skills/skills/securability-engineering in OWASP/secure-agent-playbook) into .agents/skills/securability-engineering in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add OWASP/secure-agent-playbook --skill securability-engineering -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/securability-engineering, .gemini/skills/securability-engineering, .github/skills/securability-engineering and .opencode/skills/securability-engineering in your project.
SKILL.md names no scripts, command-line tools or credentials: Securability Engineering is instructions for the agent only.
SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Securability Engineering is published under the CC-BY-4.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 5.8k tokens (SKILL.md is roughly 23k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Securability Engineering: Notion Pm (borghei/Claude-Skills, 874 stars), App Spec Packager (instructa/agent-skills, 139 stars), Grilling Ideas (opsmill/infrahub, 529 stars) and Avoid Feature Creep (waynesutton/builder-skills, 404 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
OWASP (a GitHub organization) maintains it in OWASP/secure-agent-playbook, which has 186 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on September 25, 2026.
Source: OWASP/secure-agent-playbook on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.