secure-builder-claude-skill
Apply secure defaults before writing security-sensitive software
Apply secure defaults before writing security-sensitive software
secure-builder activates when a Claude Code task touches authentication, uploads, user-supplied URLs, secrets, deployment settings, Dockerfiles, CI workflows, dependencies, or pre-commit checks. It plans threats first, then applies patterns for password storage, validation, SSRF, file handling, cookies, token rotation, container hardening, CI permissions, and security tests. The skill can also guide a private-repository bootstrap with scanning and branch rules. Routine refactors, renames, and pure UI work stay outside its trigger scope.
Resource types
Use cases
Platforms
Audit suspension risks in a Claude Code working environment.
Check whether a specific CVE actually applies to your environment.
Capabilities
Public GitHub facts last synced Jul 10, 2026.
Store and inject development secrets through 1Password from Claude Code.
Audit a deployed public app for production gaps missed during coding.