Back to skills
SKILL.md
Security Privacy
ASecurityPre-flight security & privacy checklist for changes touching identity, data, logging, or external integrations; ensures secrets/PII hygiene and boundary-safe design.
- 207 stars
- 0 votes
- 0 copies
- 2 views
- Added September 4, 2026
Works with
Security analysis
100/100Pro scans all 13 files and shows the line behind each finding
npx -y skills add NeverSight/skills_feed --skill security-privacy --agent claude-codeAre you the author of Security Privacy?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/neversight-security-privacy)---
name: security-privacy
description: Pre-flight security & privacy checklist for changes touching identity, data, logging, or external integrations; ensures secrets/PII hygiene and boundary-safe design.
---
# Security & Privacy (Pre-flight)
## Use when
- Adding/reading/writing user/workspace data.
- Touching identity/auth, permissions, Firebase rules, or external APIs.
- Adding logging, analytics, telemetry, or error reporting.
## Workflow
1. Identify data: what fields are PII, where stored, retention expectations.
2. Identify trust boundaries: browser ↔ Firebase/backend; who can call what.
3. Minimize & redact: remove unnecessary fields; ensure logs/errors redact secrets/PII.
4. Validate inputs at the edge; keep Domain pure.
5. Confirm least privilege: tokens, rules, and access paths.
## Output checklist
- No secrets in repo, fixtures, or logs.
- No PII in logs/errors/templates.
- Clear authorization point (not scattered across UI).
- Deletion path does not leave access holes.
## References
- `.github/instructions/65-security-privacy-copilot-instructions.md`
Files in this skill
- SKILL.md
- description_ar.txt
- description_cn.txt
- description_de.txt
- description_en.txt
- description_es.txt
- description_fr.txt
- description_it.txt
- description_ja.txt
- description_ko.txt
- description_ru.txt
- description_tw.txt
- stats.json
Attribution
Comments
Loading comments…