All skills
asyrafhussin avatar

/project-docs

@6cadc91

Project documentation lifecycle for PHP/Laravel and Node/TypeScript/React projects — bootstrapping essential docs, naming and folder conventions, freshness, and cleanup of AI-generated junk and stale files. Use when starting a new project, setting up docs/ structure, auditing markdown files, cleaning up the docs folder, or deciding which docs to keep, archive, or delete. Triggers on "set up docs", "audit docs", "clean up markdown", "what docs does this project need", "organize docs folder", "find stale docs".

Use this Skill: https://skilld.dev/gh/asyrafhussin/agent-skills/project-docs

This session only. Nothing lands on disk.

rulesessential-security.md

≈908 tokens on demand. Your agent reads this file only when SKILL.md points to it.

SECURITY.md — Vulnerability Reporting Policy

Impact: HIGH (Without a clear policy, researchers go public; with one, they email you privately)

A SECURITY.md tells security researchers how to report a vulnerability to you privately. Without it, well-intentioned researchers either open a public GitHub issue (instant CVE) or give up and never report. GitHub's "Security" tab links directly to this file.

When required

  • Any internet-facing service — required
  • Open-source libraries — required from first public release
  • Internal-only projects — optional, but useful for clarity even internally
  • Closed-source applications used by customers — recommended

Recommended structure

# Security Policy

## Supported versions

We provide security updates for the following versions:

| Version | Supported |
|---------|-----------|
| 3.x     | ✅        |
| 2.x     | ✅ (until 2026-12) |
| 1.x     | ❌ (EOL)  |

## Reporting a vulnerability

**Please do not file a public GitHub issue for security vulnerabilities.**

Email us at **security@example.com** with:
- A description of the issue
- Steps to reproduce
- Affected versions (if known)
- Any proof-of-concept code (optional)

We acknowledge reports within **2 business days** and aim to issue a fix within **30 days** for high/critical severity.

If you prefer encrypted communication, our PGP key is at <https://example.com/security.asc>.

## Disclosure timeline

- Day 0: We receive your report and acknowledge
- Day 1–14: Triage, reproduce, develop fix
- Day 15–30: Release patched version, notify users
- Day 30+: Public disclosure (we'll credit you unless you prefer anonymity)

## Safe harbor

We will not pursue legal action against researchers who:
- Make a good-faith effort to follow this policy
- Avoid privacy violations, service disruption, or destruction of data
- Give us reasonable time to remediate before public disclosure

Incorrect

❌ No SECURITY.md at all on a public web app

(No mechanism for reporting; researchers either guess an email or go public.)
❌ "Just open an issue"

# Security

If you find a security issue, please open a GitHub issue.

(This guarantees public disclosure of vulnerabilities — the worst possible default.)

Use GitHub's built-in private reporting

GitHub supports Private Security Advisories — researchers can report via the Security tab without exposing the issue publicly. Enable in Settings → Security → "Private vulnerability reporting". Reference it in SECURITY.md:

You may also use **GitHub's private vulnerability reporting**:
<https://github.com/org/repo/security/advisories/new>

Detection

# Internet-facing? Public repo? — should have SECURITY.md
test -f SECURITY.md || test -f .github/SECURITY.md \
  || echo "MISSING SECURITY.md (required for public/internet-facing projects)"

Reference: GitHub — Adding a security policy · GitHub Private Vulnerability Reporting · Disclose.io safe-harbor template

Source: SKILL.md on GitHub

No alerts16d3 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The skill is a comprehensive documentation lifecycle management tool for PHP/Laravel and Node.js projects. It provides a set of 25 rules for organizing, naming, and maintaining project documentation. The analysis found no security issues; the skill utilizes standard auditing practices and suggests well-known industry tools for documentation linting and quality assurance.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

Signed by skilld at 6cadc91. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub last month.

Steadyupdated 5 months ago
metadata
{
  "author": "agent-skills",
  "version": "1.0.0"
}

README badge

README badge for asyrafhussin/agent-skills/project-docs