Machine-facing entrypoint for this repository. Use this file for direct corpus navigation. Use README.md for install steps, release channels, and human onboarding.
- Read SKILL.md for trigger logic and routing rules.
- Always load references/_core-invariants.md once.
- Load only the domain files needed for the current task.
- Use references/_index.md only when category, review date, or audit-level metadata is needed.
Category sections below are intentionally compact, representative entrypoints. For the exhaustive live corpus, use references/_index.md.
- references/appsec/owasp-top10.md
- references/appsec/api-security.md
- references/appsec/graphql-security.md
- references/appsec/threat-modeling.md
- references/appsec/security-testing-examples.md
- references/appsec/security-diff-review.md
- references/appsec/ai-code-secure-remediation.md
- references/appsec/ssrf-deserialization-command-injection.md
- references/appsec/secure-headers.md
- references/appsec/browser-security-modern.md
- references/appsec/frontend-frameworks-security.md
- references/appsec/language-patterns.md
- references/appsec/production-error-handling.md
- references/appsec/webhooks-security.md
- references/appsec/database-security.md
- references/appsec/applied-cryptography.md
- references/appsec/security-myths.md
- references/appsec/framework-examples.md
- references/infra/supply-chain-security.md
- references/infra/github-actions-hardening.md
- references/infra/terraform-iac-hardening.md
- references/infra/terraform-policy-as-code-recipes.md
- references/infra/cloud-container-runnable-hardening-tests.md
- references/infra/secrets-manager-boundaries-and-injection-patterns.md
- references/infra/container-k8s-hardening.md
- references/infra/rate-limiting-infrastructure.md
- references/infra/iot-ot-security.md
- references/infra/policy-exception-handling.md
- references/iam/authorization-rbac.md
- references/iam/authorization-regression-testing.md
- references/iam/session-management.md
- references/iam/webauthn-fido2.md
- references/iam/cloud-iam-hardening.md
- references/iam/active-directory-hardening.md
- references/iam/sso-saml-oidc-hardening.md
- references/iam/workload-identity-federation.md
- references/iam/machine-identity-and-service-accounts.md
- references/iam/service-account-inventory-and-ownership.md
- references/iam/temporary-access-and-break-glass-governance.md
- references/iam/identity-lifecycle-jml.md
- references/platform/mobile-security.md
- references/platform/desktop-app-security.md
- references/platform/memory-safety-hardening.md
- references/platform/browser-isolation-and-profile-segmentation.md
- references/platform/high-trust-admin-workstations.md
- references/platform/endpoint-vba-security.md
- references/platform/developer-workstation-secrets-and-local-ai.md
- references/platform/electron-update-and-auto-update-hardening.md
- references/platform/mdm-baselines-intune-jamf-kandji.md
- references/platform/remote-browser-isolation-and-disposable-browsing.md
- references/platform/saas-admin-browser-separation.md
- references/ai/_index.md
- references/ai/llm-agent-security.md
- references/ai/browser-computer-use-security.md
- references/ai/mcp-security.md
- references/ai/rag-retrieval-security.md
- references/ai/hostile-corpus-review.md
- references/ai/ai-cli-hardening.md
- references/ai/ai-ide-no-code-security.md
- references/ai/ai-tool-profiles.md
- references/ai/agent-evals-red-teaming.md
- references/ai/agent-approval-patterns.md
- references/ai/prompt-and-tool-evidence-handling.md
- references/ai/multi-agent-boundaries-and-delegation.md
- references/ai/connector-and-integration-governance.md
- references/ai/ai-system-release-gates.md
- references/ai/quick-start-ai-coding.md
- references/ai/vibecoder-traps.md
- references/ai/ai-agent-incident-response.md
- references/ai/agent-memory-and-context-retention.md
- references/privacy/privacy-data-minimization.md
- references/privacy/gdpr-security-ops.md
- references/privacy/data-classification-and-handling.md
- references/privacy/ai-prompt-data-handling.md
- references/privacy/privacy-review-for-ai-vendors.md
- references/privacy/retention-enforcement-and-deletion-evidence.md
- references/privacy/screenshot-and-support-artifact-handling.md
- references/privacy/cross-border-ai-data-transfer-review.md
- references/privacy/dsar-export-erasure-runbook.md
- references/privacy/privacy-safe-analytics-and-product-instrumentation.md
- references/privacy/ropa-dpia-dpa-scc-tia-template-pack.md
- references/privacy/vendor-and-processor-tiering.md
- references/ops/defensive-security-baseline.md
- references/ops/secret-leak-prevention.md
- references/ops/pre-push-checklist.md
- references/ops/security-audit-levels.md
- references/ops/security-improvements.md
- references/ops/security-metrics-kpis.md
- references/ops/detection-engineering.md
- references/ops/detection-translations.md
- references/ops/incident-playbooks.md
- references/ops/secure-workstation-builds.md
- references/ops/security-backlog-triage-and-prioritization.md
- references/ops/vuln-management.md
- references/ops/social-engineering-physical.md
- references/compliance/cwe-owasp-mapping.md
- references/compliance/compliance-mapping.md
- references/compliance/coverage-matrix.md
- references/compliance/audit-sample-request-response.md
- references/compliance/customer-security-questionnaire-response-pack.md
- references/compliance/evidence-redaction-and-sharing-rules.md
- references/compliance/regulator-notification-decision-matrix.md
- references/compliance/control-ownership-and-review-cadence.md
- references/compliance/nis2-dora-operational-evidence.md
- references/compliance/soc2-iso27001-evidence-packs.md
python scripts/build-index.pypython scripts/lint-skill.pypython evals/run.py