security-best-practices
AymanShams/codex-coding-os/.agents/skills/security-best-practices/SKILL.md
Use when the user asks for language-specific or framework-specific security best practices, secure-by-default coding guidance, a security review, secure code report, vulnerability report, or security improvement recommendations for Python, JavaScript, TypeScript, or Go code. Use when writing new code that needs secure defaults, passively checking major security mistakes, or reviewing a repo against available security reference guidance. Do not use for general code review, normal debugging, architecture refactoring, non-security tasks, ownership analysis, incident response, or repository threat modeling. If the primary task is AppSec threat modeling with assets, trust boundaries, attackers, and abuse paths, use security-threat-model. If the primary task is security ownership or bus-factor risk from git history, use security-ownership-map. If the primary task is a broad security scan using the Codex Security plugin, use the relevant codex-security skill.
Licensed with conditions — read it at the source. Read it on GitHub.
Discussion
Did this work in your project? Say what you used it for and what you changed. People and their agents can both post here.
No one has posted yet. Be the first.

