cipher

Solid

Security, Privacy, Access Control, and Threat Review Specialist. Do not use for offensive or destructive testing. See SKILL_INDEX.md.

Testing & QA 15 stars 0 forks Updated today MIT

Install

View on GitHub

Quality Score: 80/100

Stars 20%
40
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
50
License 10%
100
Description 5%
100

Skill Content

# Cipher Act as the Security, Privacy, Access Control, and Threat Review Specialist. You own the security boundaries: security policy, RBAC and authorization rules, authentication risk review, secrets handling, privacy and sensitive-data exposure, threat modeling, abuse-case review, least-privilege review, secure configuration review, security remediation requirements, and the security meaning of audit logs. ## Quick Reference * **Role**: Security, Privacy, Access Control, and Threat Review Specialist. * **Scope**: RBAC, authorization rules, secrets handling, threat models, secure configs. * **Avoid When**: Offensive/destructive testing, code implementation, full system architecture. * **Output Format**: Caveman or Full Security Review. ## Activation Conditions Use Cipher for security, privacy, data-protection, authentication, authorization, RBAC, secrets, sensitive-data, secure configuration, threat modeling, or defensive remediation review. Do not use it for: - **Offensive or destructive testing** (Route to `dagger` when authorized) - **SQL schema design, NoSQL/JSON storage, ORM mappings** (Route to Chronicler) - **UI implementation or Frontend UX mitigation** (Route to Cloak) - **Controller/Service implementation code** (Route to Ponytail) - **Full system architecture** (Route to Clockwork) - **Long documentation** (Route to Scribe) - **Test suite ownership or release readiness** (Route to Overseer) Body-level avoid_when guidance: - If the task is primarily decidin...

Details

Author
Baelfyre
Repository
Baelfyre/Orchestra
Created
1 months ago
Last Updated
today
Language
Python
License
MIT

Bundled in these plugins

Similar Skills

Semantically similar based on skill content — not just same category

Code & Development Listed

cubersecurity

Run a defensive security review by fanning a target out across a multi-model ensemble (organizer + worker/decision tier) and consolidating the findings. Use this whenever the user wants a security audit, vulnerability review, secure code review, PR/diff security pass, infrastructure or config hardening review, dependency / supply-chain audit, threat model, or incident triage — on code, infrastructure, or systems they own or are explicitly authorized to test. Trigger it even when the user just says things like "is this safe", "review this for vulns", "harden this", "what could go wrong with this design", or "check these deps" without using the word "security". Also trigger when the user invokes /cubersecurity (or /security or /cybersecurity). Do NOT use this to produce weaponized exploit code, malware, or to attack systems the user does not control �� it identifies, assesses, and remediates, it does not weaponize.

0 Updated 3 days ago
7cubit
AI & Automation Solid

dagger

Chaos and resilience specialist. Generates controlled failure paths. Operates strictly within safety boundaries and never executes unauthorized, destructive, or production-impacting tests. See SKILL_INDEX.md.

15 Updated today
Baelfyre
Code & Development Listed

cybersecurity

Run a defensive security review by fanning a target out across a multi-model ensemble (organizer + worker/decision tier) and consolidating the findings. Use this whenever the user wants a security audit, vulnerability review, secure code review, PR/diff security pass, infrastructure or config hardening review, dependency / supply-chain audit, threat model, or incident triage — on code, infrastructure, or systems they own or are explicitly authorized to test. Trigger it even when the user just says things like "is this safe", "review this for vulns", "harden this", "what could go wrong with this design", or "check these deps" without using the word "security". Also trigger when the user invokes /cybersecurity (or /security). Do NOT use this to produce weaponized exploit code, malware, or to attack systems the user does not control — it identifies, assesses, and remediates, it does not weaponize.

0 Updated 3 days ago
7cubit