Topics
- authentication
- authorization
- encryption
- security-architecture
- access-control
- threat-modeling
- token-handling
- data-protection
- trust-boundaries
- cryptography
What it does
Evaluates system designs for authentication, authorization, data protection, and cryptographic correctness against established security patterns. Covers token handling, session management, role-based access control, encryption at rest and in transit, and trust boundary validation.
Generated from the current SKILL.md.
Frequently asked
Does this skill cover both authentication and authorization?
Yes. It reviews token handling, session management, credential storage, role-based access control, and object-level authorization patterns.
What encryption standards does this skill evaluate?
It checks for AES-256 or equivalent at rest, TLS 1.2+ in transit, envelope encryption with key management, and end-to-end encryption in vault architectures.
Does this skill identify trust boundaries in system design?
Yes. It maps common trust boundaries (client-to-API, service-to-database, browser-to-extension) and validates input, authentication, authorization, and logging at each crossing.
Can this skill review password storage practices?
Yes. It evaluates whether passwords are hashed with modern KDFs like Argon2id, bcrypt, or PBKDF2, with unique salts and appropriate work factors.
Does this skill assess zero-trust principles in internal networks?
Yes. It reviews whether internal service-to-service calls enforce authentication, authorization, and encryption, rather than trusting network location alone.
Generated from the current SKILL.md. These answers refresh after source changes.