CCPM Project Management
automazeio/ccpm
Runs a spec-driven workflow from PRD to epic to GitHub issues to parallel agents, with status, standup and blocked-work reports from bundled scripts.
Score a codebase, file, or merge request against the FIASSE v1.0.4 SSEM model — 0-10 per attribute, equal-weighted pillars, evidence-backed strengths and weaknesses, prioritized recommendations…
$ npx skills add OWASP/secure-agent-playbook --skill securability-engineering-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install OWASP/secure-agent-playbook securability-engineering-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/OWASP/secure-agent-playbook.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/code-security-skills/skills/securability-engineering-review .claude/skills/securability-engineering-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "securability-engineering-review" agent skill from https://github.com/OWASP/secure-agent-playbook/tree/main/plugins/code-security-skills/skills/securability-engineering-review into .claude/skills/securability-engineering-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "securability-engineering-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/OWASP/secure-agent-playbook/tree/main/plugins/code-security-skills/skills/securability-engineering-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add OWASP/secure-agent-playbook --skill securability-engineering-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install OWASP/secure-agent-playbook securability-engineering-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OWASP/secure-agent-playbook.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/code-security-skills/skills/securability-engineering-review .agents/skills/securability-engineering-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "securability-engineering-review" agent skill from https://github.com/OWASP/secure-agent-playbook/tree/main/plugins/code-security-skills/skills/securability-engineering-review into .agents/skills/securability-engineering-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "securability-engineering-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add OWASP/secure-agent-playbook --skill securability-engineering-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install OWASP/secure-agent-playbook securability-engineering-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OWASP/secure-agent-playbook.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/code-security-skills/skills/securability-engineering-review .cursor/skills/securability-engineering-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "securability-engineering-review" agent skill from https://github.com/OWASP/secure-agent-playbook/tree/main/plugins/code-security-skills/skills/securability-engineering-review into .cursor/skills/securability-engineering-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "securability-engineering-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/OWASP/secure-agent-playbook.git --path plugins/code-security-skills/skills/securability-engineering-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add OWASP/secure-agent-playbook --skill securability-engineering-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install OWASP/secure-agent-playbook securability-engineering-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OWASP/secure-agent-playbook.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/code-security-skills/skills/securability-engineering-review .gemini/skills/securability-engineering-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "securability-engineering-review" agent skill from https://github.com/OWASP/secure-agent-playbook/tree/main/plugins/code-security-skills/skills/securability-engineering-review into .gemini/skills/securability-engineering-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "securability-engineering-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install OWASP/secure-agent-playbook securability-engineering-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add OWASP/secure-agent-playbook --skill securability-engineering-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/OWASP/secure-agent-playbook.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/code-security-skills/skills/securability-engineering-review .github/skills/securability-engineering-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "securability-engineering-review" agent skill from https://github.com/OWASP/secure-agent-playbook/tree/main/plugins/code-security-skills/skills/securability-engineering-review into .github/skills/securability-engineering-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "securability-engineering-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add OWASP/secure-agent-playbook --skill securability-engineering-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install OWASP/secure-agent-playbook securability-engineering-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OWASP/secure-agent-playbook.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/code-security-skills/skills/securability-engineering-review .opencode/skills/securability-engineering-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "securability-engineering-review" agent skill from https://github.com/OWASP/secure-agent-playbook/tree/main/plugins/code-security-skills/skills/securability-engineering-review into .opencode/skills/securability-engineering-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "securability-engineering-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
securability-engineering-reviewScore a codebase, file, or merge request against the FIASSE v1.0.4 SSEM model — 0-10 per attribute, equal-weighted pillars, evidence-backed strengths and weaknesses, prioritized recommendations…
Securability Engineering Review is an agent skill from OWASP/secure-agent-playbook. Score a codebase, file, or merge request against the FIASSE v1.0.4 SSEM model — 0-10 per attribute, equal-weighted pillars, evidence-backed strengths and weaknesses, prioritized recommendations, 50-item checklist appendix. Trigger on "review/score/audit securability", "SSEM scorecard", "FIASSE/SSEM compliance", "where would I start hardening this?", "is this audit-ready?", "security posture baseline" — including phrasings that don't say SSEM explicitly. For requirements use prd-securability-enhancement; for new…
Its SKILL.md is about 4.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file.
It sits in Product & Project Management, covering PRD writing. The repository describes itself as: OWASP Secure Agent Playbook Project. The licence is CC-BY-4.0.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 1b5fd4c. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are python).
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Securability Engineering Review loads about 4.6k tokens when it runs. Until then it costs about 146 tokens; SKILL.md has 2,106 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from OWASP/secure-agent-playbook at commit 1b5fd4c, republished under its CC-BY-4.0 licence (© OWASP). 2,106 words, ~4,633 tokens.
.claude/skills/securability-engineering-review/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Analyze code for securable engineering qualities and produce a structured SSEM scorecard. This file is authoritative for the rubric, weights, severity classification, and report shape. The play at plays/securability-engineering-review.md is the step-by-step runbook; consult it for when to do each step, not for what the rubric says.
Aligned with FIASSE v1.0.4. Per-attribute measurement guidance in data/fiasse/SA.*.md (Appendix A).
Trigger this skill when the user asks to:
Adjacent phrasings: "rate this code for security", "is this audit-ready?", "what's the security health of X?", "how securable is this?", "do a sec-engineering review", "give me a posture report".
Each attribute is scored 0-10. Pillar scores are simple averages of their attribute scores. The overall SSEM score is the simple average of the three pillar scores.
| Pillar | Pillar Weight | Attributes | Per-Attribute Weight |
|---|---|---|---|
| Maintainability | 1/3 | Analyzability, Modifiability, Testability, Observability | 1/4 each |
| Trustworthiness | 1/3 | Confidentiality, Accountability, Authenticity | 1/3 each |
| Reliability | 1/3 | Availability, Integrity, Resilience | 1/3 each |
Pillar score = average of its attribute scores. Overall SSEM score = (Maintainability + Trustworthiness + Reliability) / 3.
Equal weighting reflects FIASSE v1.0.4's stance that no SSEM attribute is intrinsically more important than another — context-specific severity is captured in findings, not in the rubric.
| Score | Anchor |
|---|---|
| 10 | Exemplary implementation |
| 8 | Strong implementation with minor issues |
| 6 | Adequate implementation with notable gaps |
| 4 | Weak implementation with significant issues |
| 2 | Minimal or poor implementation |
Interpolation between anchors is allowed when justified by evidence. Stay consistent with the rubric language.
Every report MUST produce a numeric 0-10 score for each of these:
Maintainability
Trustworthiness 5. Confidentiality (FIASSE v1.0.4 S3.2.2.1) — sensitive-data handling, least privilege, encryption 6. Accountability (FIASSE v1.0.4 S3.2.2.2) — audit trails, action traceability 7. Authenticity (FIASSE v1.0.4 S3.2.2.3) — identity verification, token integrity, non-repudiation
Reliability 8. Availability (FIASSE v1.0.4 S3.2.3.1) — resource limits, timeouts, graceful degradation 9. Integrity (FIASSE v1.0.4 S3.2.3.2) — input handling, parameterized queries, derived state 10. Resilience (FIASSE v1.0.4 S3.2.3.3) — error handling, recovery, defensive coding
| Score Range | Grade | Description |
|---|---|---|
| 9.0–10.0 | Excellent | Exemplary implementation, minimal improvement needed |
| 8.0–8.9 | Good | Strong implementation, minor improvements beneficial |
| 7.0–7.9 | Adequate | Functional but notable improvement opportunities exist |
| 6.0–6.9 | Fair | Basic requirements met, significant improvements needed |
| < 6.0 | Poor | Critical deficiencies requiring immediate attention |
Severity is an engineering-impact judgment, not a CVSS or CWE score. FIASSE does not borrow assurance-tool severity scales. Classify each finding by its effect on SSEM scores and on the system's ability to remain securable.
| Severity | Criteria |
|---|---|
| CRITICAL | A pillar score is held ≤4 because of this finding alone; or an attribute scores ≤2 due to systemic absence (e.g., no input validation anywhere, no audit trail, ambient client-trust). Remediation requires architectural change. |
| HIGH | A single attribute scores ≤4 due to this finding; or the finding reduces a pillar score by ≥1.5 points. Localized but pervasive (e.g., string-built SQL across one service). |
| MEDIUM | Reduces a single attribute by ~1 point; specific module or pattern. Remediation contained to one module. |
| LOW | Localized engineering improvement; ≤0.5 score impact. |
| INFO | Best-practice observation; no measurable score impact. |
If the repository or input is incomplete, ask for these before scoring:
If essential context is missing, score conservatively and state the limitation explicitly. Do not invent coverage, architecture, or operational controls.
Full read-through is impossible at scale. Sample deliberately and declare what was sampled. The report's credibility rests on the sampling discipline, not on claimed totality.
Inspection priority order:
For each sampled area, mark the report with the file paths actually inspected. For un-sampled areas, score conservatively (cap at 6) and call out the gap in the assessment line. Do not extrapolate from sampled to un-sampled with confidence.
For very large repos, scope the review to a single service / package / module and say so in the scope statement. A focused scorecard is worth more than a vague one covering everything.
The full step-by-step runbook lives in plays/securability-engineering-review.md. The high-level shape:
The report must contain exactly these three parts in order. Do not skip parts even on small reviews.
A compact summary block. The exact ASCII shape can flex (Markdown tables are also acceptable when the review is short), but it must include:
Per pillar, write:
1. **[Title]** (Severity: CRITICAL/HIGH/MEDIUM/LOW/INFO)
- Issue: [Specific problem]
- Impact: [Effect on the pillar score and on the system]
- Solution: [Actionable steps]
- Expected Improvement: +[X.X] pointsFor per-finding format, use templates/finding.md. For full-report scaffold, use templates/report.md.
The official checklist:
Mark each [x] (passing) or [ ] (failing) with a brief inline note when failing.
End with a checklist summary:
Snippet under review (Python, ~12 lines):
@app.post("/notes/{note_id}")
def update_note(note_id, body):
sql = f"UPDATE notes SET body = '{body}' WHERE id = {note_id}"
db.execute(sql)
print("note updated " + note_id)
return {"ok": True}Analyzability — 4/10 (weak). Single-purpose handler but unsafe string formatting; no input typing; no early returns; conflates parsing, persistence, and response shaping.
Evidence: f"UPDATE notes SET body = '{body}' WHERE id = {note_id}".
Observability — 2/10 (minimal). print(...) is not structured output. No correlation ID, no actor, no outcome field. Failure paths are silent.
Evidence: print("note updated " + note_id).
Integrity — 2/10 (minimal). SQL injection via string interpolation; no parameterized queries; no ownership check (any caller can update any note ID — Derived Integrity violation per FIASSE v1.0.4 S4.4.1.2).
Evidence: same line as above; no current_user derivation.
Accountability — 3/10 (weak). print is not an audit log; missing actor, action verb, target ID type-tagged, and outcome.
Evidence: print("note updated " + note_id).
Recommendation (HIGH) — Replace the f-string with a parameterized query that scopes by owner, and emit a structured note.update log with {actor, note_id, outcome}. Expected improvement: Integrity +5, Accountability +3, Observability +4, Analyzability +2.
This is the level of specificity the report should hit at scale — every score paired with a code-anchored observation, every weakness with a remediation that names the change.
When you find one of these patterns, tag the finding with the FIASSE/SSEM principle it violates. Specific named tagging is what makes a report actionable — saying "the code mishandles auth" is weak; saying "this is a Derived Integrity violation (FIASSE v1.0.4 S4.4.1.2) — the server's authorization decision rests on a client-asserted JWT claim" is strong.
| Pattern observed in code | Principle / attribute violated | Tag in finding |
|---|---|---|
Server decides who-can-do-what based on a client-asserted claim (req.user.email, request.body.user_id, X-Tenant-ID header) | Integrity — Derived Integrity Principle (FIASSE v1.0.4 S4.4.1.2) | "Derived Integrity violation" |
Spread of req.body / **kwargs directly into a database update or model field-set | Integrity — Request Surface Minimization (FIASSE v1.0.4 S4.4.1.1) | "Request Surface Minimization violation; mass assignment" |
| String-built SQL or shell commands; format strings with user input | Integrity — input handling at trust boundary (FIASSE v1.0.4 S4.4.1, S4.3) | "Trust boundary input handling" |
Path joined with user-controlled segment without ../separator validation | Integrity — trust boundary; canonicalize → sanitize → validate (FIASSE v1.0.4 S4.4.1) | "Path canonicalization gap" |
jwt.verify with no pinned algorithms / no audience / no issuer; or using a default-allow algorithm list | Authenticity (token integrity) | "Token verification under-specified" |
console.log / print / fmt.Println standing in for an audit trail; missing actor, target, outcome, request id | Accountability + Observability (FIASSE v1.0.4 S2.5, S3.2.1.4) | "Unstructured audit trail" |
Bare except: / catch (e) returning raw exception text to the client | Resilience (graceful degradation); Confidentiality (info leakage) | "Specific exception handling missing" |
| Module-level globals (DB connection, app, config) created at import time | Modifiability (loose coupling); Testability (mockability) | "Import-time side effects" |
ioutil.ReadAll(r.Body) / unlimited request body buffer | Availability + Resilience (resource limits) | "Unbounded resource consumption" |
Pervasive any typing on the trust-boundary surface (TypeScript / dynamic langs) | Analyzability; Integrity (validation) | "Trust-boundary type erasure" |
Silent try { … } catch {} / failure paths that emit no log or metric | Observability (failure-path visibility) (FIASSE v1.0.4 S3.2.1.4) | "Silent failure" |
| Health/metrics endpoints absent; readiness/liveness derived from external probes only | Observability (instrumentation built into code, not bolted on externally) (FIASSE v1.0.4 S3.2.1.4) | "External-only instrumentation" |
You don't need this whole table inline in every report. But when one of these patterns is present, the finding should name the principle by tag — not just describe the symptom.
except: at app/handlers.py:42 with except (ValidationError, NotFound) as e:" is.Always:
When invoked:
data/fiasse/SA.*.mddata/asvs/© OWASP, CC-BY-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in plugins/code-security-skills/skills/securability-engineering-review of OWASP/secure-agent-playbook.
Open the folder on GitHubat commit 1b5fd4c
Securability Engineering Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Securability Engineering Review this skillOWASP/secure-agent-playbook | 187 | — | ~4.6k | Automated safety check: Pass | CC-BY-4.0 | |
| CCPM Project Managementautomazeio/ccpm | 8.4k | — | ~1.1k | Automated safety check: Pass | MIT | |
| Ralph Tui Create Beadssubsy/ralph-tui | 2.5k | 1 repos | ~2.6k | Automated safety check: Pass | MIT | |
| Trellis Brainstormanjiemo/SunnyBeach | 178 | 7 repos | ~4k | Automated safety check: Pass | Apache-2.0 | |
| Ralph Tui Create Beads Rustsubsy/ralph-tui | 2.5k | 1 repos | ~2.8k | Automated safety check: Pass | MIT | |
| Ralph Tui Create JSONsubsy/ralph-tui | 2.5k | 1 repos | ~2.6k | Automated safety check: Pass | MIT |
automazeio/ccpm
Runs a spec-driven workflow from PRD to epic to GitHub issues to parallel agents, with status, standup and blocked-work reports from bundled scripts.
subsy/ralph-tui
Convert PRDs to beads for ralph-tui execution. An agent skill from subsy/ralph-tui.
anjiemo/SunnyBeach
Guides collaborative requirements discovery before implementation.
subsy/ralph-tui
Convert PRDs to beads for ralph-tui execution using beads-rust (br CLI).
subsy/ralph-tui
Convert PRDs to prd.json format for ralph-tui execution. An agent skill from subsy/ralph-tui.
jamesrochabrun/skills
Generate comprehensive Product Requirements Documents (PRDs) for product managers.
OWASP/secure-agent-playbook
Enhance PRDs, feature specs, user stories, or product briefs with explicit OWASP ASVS coverage and FIASSE v1.0.4 SSEM implementation guidance — before code is written.
OWASP/secure-agent-playbook
Generate, scaffold, or refactor code so it embodies FIASSE v1.0.4 SSEM qualities by default — 10 attributes, Transparency and Least-Astonishment principles, ASVS-aligned controls, defensive boundary…
OWASP/secure-agent-playbook
Audit AI agent configurations for security risks — excessive permissions, prompt injection surfaces, data exfiltration paths, and missing guardrails.
OWASP/secure-agent-playbook
Comprehensive AI security verification using OWASP AI Security Verification Standard (AISVS) framework.
OWASP/secure-agent-playbook
Comprehensive API security review against OWASP API Security Top 10 (2023).
OWASP/secure-agent-playbook
Security-focused code review mapped to OWASP Top 10 and ASVS.
Categories
Score a codebase, file, or merge request against the FIASSE v1.0.4 SSEM model — 0-10 per attribute, equal-weighted pillars, evidence-backed strengths and weaknesses, prioritized recommendations…. Securability Engineering Review is an agent skill from OWASP/secure-agent-playbook.4 SSEM model — 0-10 per attribute, equal-weighted pillars, evidence-backed strengths and weaknesses, prioritized recommendations, 50-item checklist appendix.
Securability Engineering Review fits situations like: review/score/audit securability; FIASSE/SSEM compliance; where would I start hardening this?; is this audit-ready?.
Run `npx skills add OWASP/secure-agent-playbook --skill securability-engineering-review -a claude-code`. Or copy the skill folder (plugins/code-security-skills/skills/securability-engineering-review in OWASP/secure-agent-playbook) into .claude/skills/securability-engineering-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add OWASP/secure-agent-playbook --skill securability-engineering-review -a codex`. Or copy the skill folder (plugins/code-security-skills/skills/securability-engineering-review in OWASP/secure-agent-playbook) into .agents/skills/securability-engineering-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add OWASP/secure-agent-playbook --skill securability-engineering-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/securability-engineering-review, .gemini/skills/securability-engineering-review, .github/skills/securability-engineering-review and .opencode/skills/securability-engineering-review in your project.
SKILL.md names no scripts, command-line tools or credentials: Securability Engineering Review is instructions for the agent only. Our summary lists: Python 3.
SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Securability Engineering Review is published under the CC-BY-4.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.6k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Securability Engineering Review: CCPM Project Management (automazeio/ccpm, 8.4k stars), Ralph Tui Create Beads (subsy/ralph-tui, 2.5k stars), Trellis Brainstorm (anjiemo/SunnyBeach, 178 stars) and Ralph Tui Create Beads Rust (subsy/ralph-tui, 2.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
OWASP (a GitHub organization) maintains it in OWASP/secure-agent-playbook, which has 187 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on September 25, 2026.
Source: OWASP/secure-agent-playbook on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.