← ClaudeAtlas

forge-securitylisted

Perform a threat-informed audit of trust boundaries, injection, secrets, browser controls, dependencies, and abuse cases. Use for every production-bound application.
seroneyemmanuel4-afk/fullstack-forge-skill · ★ 0 · API & Backend · score 72
Install: claude install-skill seroneyemmanuel4-afk/fullstack-forge-skill
# forge-security: Application security ## Purpose Perform a threat-informed audit of trust boundaries, injection, secrets, browser controls, dependencies, and abuse cases. Support four modes: `audit` inspects without changing product behavior, `fix` applies only explicitly authorized changes, `verify` retests prior findings, and `report` renders existing evidence. If no mode is supplied, use `audit`. ## Trigger conditions Use this module when a request names `forge-security`, asks about application security, or discovery finds an applicable boundary. Run it from the repository root after project discovery. ## When it applies - Every production-bound application - Security-sensitive changes ## When it does not apply - No exemption; scope may be reduced for non-executable documentation Do not silently skip it. Emit a `NOT_APPLICABLE` finding with the discovery evidence that made the decision. ## Inputs from project discovery - project and architecture profile - trust boundaries - dependency and secret scan outputs Prefer `.forge/project-profile.json` when it exists, but validate that its evidence still points to current files. Read `../fullstack-forge/references/PROTOCOL.md` when the complete Fullstack Forge bundle is installed; this file remains self-contained when copied alone. ## Inspection procedure 1. Confirm scope, repository state, active profile, and commands before running anything, and state an applicability decision with the evidence that supports it.