Skip to content
Back to skills

Security Privacy

ASecurity

Pre-flight security & privacy checklist for changes touching identity, data, logging, or external integrations; ensures secrets/PII hygiene and boundary-safe design.

  • 207 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 4, 2026
securityrustgitapibackendsecurity

Works with

  • api

Security analysis

A100/100

Pro scans all 13 files and shows the line behind each finding

Scanned September 4, 2026

npx -y skills add NeverSight/skills_feed --skill security-privacy --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Security Privacy?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Security Privacy
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/neversight-security-privacy/badge)](https://www.skillsdirectory.com/skills/neversight-security-privacy)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: security-privacy
description: Pre-flight security & privacy checklist for changes touching identity, data, logging, or external integrations; ensures secrets/PII hygiene and boundary-safe design.
---

# Security & Privacy (Pre-flight)

## Use when
- Adding/reading/writing user/workspace data.
- Touching identity/auth, permissions, Firebase rules, or external APIs.
- Adding logging, analytics, telemetry, or error reporting.

## Workflow
1. Identify data: what fields are PII, where stored, retention expectations.
2. Identify trust boundaries: browser ↔ Firebase/backend; who can call what.
3. Minimize & redact: remove unnecessary fields; ensure logs/errors redact secrets/PII.
4. Validate inputs at the edge; keep Domain pure.
5. Confirm least privilege: tokens, rules, and access paths.

## Output checklist
- No secrets in repo, fixtures, or logs.
- No PII in logs/errors/templates.
- Clear authorization point (not scattered across UI).
- Deletion path does not leave access holes.

## References
- `.github/instructions/65-security-privacy-copilot-instructions.md`

Files in this skill

  • SKILL.md1.1 KB
  • description_ar.txt304 B
  • description_cn.txt153 B
  • description_de.txt212 B
  • description_en.txt166 B
  • description_es.txt232 B
  • description_fr.txt263 B
  • description_it.txt217 B
  • description_ja.txt224 B
  • description_ko.txt206 B
  • description_ru.txt400 B
  • description_tw.txt153 B
  • stats.json65 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…