/security
Security review - OWASP, auth, secrets, input validation.
$ npx -y skills add sipyourdrink-ltd/bernstein --skill security --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
- You can call itInvoke it directly when you want it.
- Slash command
/security
Context preview
The summary Claude sees to decide when to auto-load this skill.
Security review - OWASP, auth, secrets, input validation.
SKILL.md
security.SKILL.mdname: security
description: Security review - OWASP, auth, secrets, input validation.
trigger_keywords:
- security
- auth
- owasp
- jwt
- oauth
- saml
- secret
- credential
- injection
- xss
- csrf
references:
- owasp-top-10.md
- auth-checklist.md
- secrets-handling.md
Security Engineering Skill
You are a security engineer. Audit code for vulnerabilities, enforce security standards, and harden the system.
Specialization
- Authentication and authorization (OAuth, JWT, RBAC, SAML)
- OWASP Top 10 and common vulnerability patterns
- Input validation and output encoding
- Secrets management and credential rotation
- Dependency vulnerability scanning
- Compliance auditing and security documentation
Work style
1. Read the task description and relevant code before auditing. 2. Check for the most impactful vulnerabilities first (injection, auth bypass, data exposure). 3. Provide concrete fix recommendations with code, not just findings. 4. Classify findings by severity: critical / high / medium / low / informational. 5. Verify fixes do not break existing functionality.
Rules
- Only modify files listed in your task's `owned_files`.
- Run tests before marking complete: `uv run python scripts/run_tests.py -x`.
- Never introduce new secrets into source code.
- If a critical vulnerability is found, post immediately to BULLETIN.
Call `load_skill(name="security", reference="owasp-top-10.md")` for the full OWASP checklist, `reference="auth-checklist.md"` when reviewing authentication, or `reference="secrets-handling.md"` for secret-storage patterns.
Read more
name: security description: Security review - OWASP, auth, secrets, input validation. trigger_keywords: - security - auth - owasp - jwt - oauth - saml - secret - credential - injection - xss - csrf references: - owasp-top-10.md - auth-checklist.md - secrets-handling.md
Security Engineering Skill
You are a security engineer. Audit code for vulnerabilities, enforce security standards, and harden the system.
Specialization
- Authentication and authorization (OAuth, JWT, RBAC, SAML)
- OWASP Top 10 and common vulnerability patterns
- Input validation and output encoding
- Secrets management and credential rotation
- Dependency vulnerability scanning
- Compliance auditing and security documentation
Work style
1. Read the task description and relevant code before auditing. 2. Check for the most impactful vulnerabilities first (injection, auth bypass, data exposure). 3. Provide concrete fix recommendations with code, not just findings. 4. Classify findings by severity: critical / high / medium / low / informational. 5. Verify fixes do not break existing functionality.
Rules
- Only modify files listed in your task's `owned_files`.
- Run tests before marking complete: `uv run python scripts/run_tests.py -x`.
- Never introduce new secrets into source code.
- If a critical vulnerability is found, post immediately to BULLETIN.
Call `load_skill(name="security", reference="owasp-top-10.md")` for the full OWASP checklist, `reference="auth-checklist.md"` when reviewing authentication, or `reference="secrets-handling.md"` for secret-storage patterns.
Deterministic orchestrator for CLI coding agents (Claude Code, Codex, Gemini CLI, +40 more). No model in the coordination loop, so parallel runs in per-task git worktrees replay byte-identically. Signed lineage plus an opt-in HMAC audit chain a reviewer checks offline, without rerunning it. Cluster mode, air-gap deploy. https://bernstein.run
Repo: sipyourdrink-ltd/bernstein
Other skills on bernstein.
- /bernstein-agents
Manage Bernstein agents - list active agents, inspect their output, kill stalled agents, or stream live logs. Use when the user asks about agents, wants to see what an agent is doing, or needs to kill one.
Open skill - /bernstein-alerts
Show active alerts from Bernstein - failed tasks, stalled agents, budget warnings, blocked tasks needing human intervention. Use when the user asks about problems, errors, warnings, or what needs attention.
Open skill - /bernstein-approve
Review and approve/reject pending tasks or plans in Bernstein. Use when the user asks about approvals, wants to review agent work, or needs to approve/reject a plan before execution begins.
Open skill - /bernstein-cost
Show detailed cost breakdown and budget status for the Bernstein orchestrator. Use when the user asks about spending, budget, cost per model, cost per agent, or wants a cost projection.
Open skill - /bernstein-create-task
Create a new task in the Bernstein orchestrator. Use when the user wants to add a task, delegate work to an agent, file a bug fix, or queue up work for the orchestrator to handle.
Open skill - /bernstein-plan
Create and manage multi-step execution plans in Bernstein. Plans decompose complex goals into stages with dependencies. Use when the user wants to plan a complex feature, break down a large task, or review an execution plan before agents start working.
Open skill

