Project overview
secure-builder activates when a Claude Code task touches authentication, uploads, user-supplied URLs, secrets, deployment settings, Dockerfiles, CI workflows, dependencies, or pre-commit checks. It plans threats first, then applies patterns for password storage, validation, SSRF, file handling, cookies, token rotation, container hardening, CI permissions, and security tests. The skill can also guide a private-repository bootstrap with scanning and branch rules. Routine refactors, renames, and pure UI work stay outside its trigger scope.
Repository facts
- Primary language
- Shell
- License
- MIT
- Repository updated
- May 3, 2026
- Default branch
- main
Resource types
General skill
Use cases
Security and privacySoftware development
Platforms
Claude Code, Codex, and more
Capabilities
PlanningVerification and evals