security-checklistslisted
Install: claude install-skill eugenelim/agent-ready-repo
<!-- agentbundle-okf: router-handoff=author-owned -->
# Skill: security-checklists
This skill is the **depth library** behind the `security-reviewer` agent. The
reviewer's body carries the *universal method* (the three-bucket delegation
rule, load-context-first, the always-on STRIDE + LINDDUN open pass, the
established-helper-bypass meta-check, the severity rubric, the honest-limits
footer, the output format). The *shape-specific depth* — what to actually
check at each trust boundary — lives here, in the per-boundary `references/<module>.md`
modules, so the agent prompt stays lean and the depth scales without bloat.
> **Reliability-vs-security carve.** This library owns *security* config; the
> *reliability / ops* side of infrastructure (idempotent convergence, blast
> radius, environment isolation, cost/teardown, drift/rollback,
> observability/smoke) lives in the [`operational-safety`](../operational-safety/SKILL.md)
> skill, consumed by `quality-engineer`. The routing splits IaC-security →
> `config-misconfig`, IaC-reliability → `operational-safety`. The two are
> complementary lenses on the same infra diff — keep the split clean both ways.
## Output rendering
<!-- agentbundle:output-rendering:start -->
Lead with the useful outcome or next action. Use warm, non-blaming language and everyday words. Define an unfamiliar term in a few plain words before naming it; keep proper names and exact technical terms intact.
During tool work, do not narrate routine calls. Send an