Skip to content
rd-skills
All skills

security-privacy-gate

ProfessionalRuntime top level

Use analysis-agent to analyze permissions, secrets, sensitive data, trust boundaries, and injection; task-agent to implement controls; and review-agent to assess evidence. Skip self-review and no-trust-impact work.

Group
Quality, security, reliability and delivery gates
Routing mode
evidence-only
Supported roles
MainAnalysisTaskReview
Source
SKILL.md

Use when

Trigger signals that make this skill the right owner

  • proved trust, privilege, permission, privacy, credential, or secret boundary change with a reachable abuse or disclosure path
  • credential or session lifecycle behavior change

Do not use when

Anti-triggers — as binding as the triggers above

  • no trust boundary impact
  • self review request
  • internal refactor with evidence that credential and session lifecycle behavior is unchanged
  • reliability-only failure with no abuse or privacy risk
  • input shape change with no security sink
  • scanner report organization without a security verdict
  • security terminology, a permission API, path mutability, or future replacement possibility without a proved trust, privilege, secret, or privacy boundary change
  • bounded same-principal non-sensitive local access with no privilege elevation or less-trusted writer

Required inputs

What must be supplied before this skill can decide anything

  • acceptance
  • trust boundary summary

Output contract

What this skill owes the next role

  • abuse-path model
  • trust-boundary changes
  • security verdict

Escalation signals

When this skill must hand the decision back

  • scope, authority, or material risk exceeds the selected task contract

Targeted references

Each reference carries its own load condition. None of them enter context by default.

ReferenceLoad whenDo not load whenRequired by
checklist.mddecision-checklistA bounded L2 mode needs compact checks for its triggered authorization, input/output, secret, dependency, privacy, cloud, AI, or tool riskThe root gate is enough or mode-specific closure and targeted proof are requiredAnalysisTaskReview
evidence-patterns.mdevidence-patternClosure depends on command/report artifacts, exit code, denied-case proof, scanner evidence, sandbox classification, freshness, or proof limitsNo selected security claim depends on runtime evidence or the root contract is sufficientAnalysisTaskReview
index.mdindexcompeting security privacy gate references require dependency, conflict, or output-fragment selectionthe security privacy gate root or a task-named reference already resolves selectionAnalysisTaskReview
security-output-and-gates.mdtargetedL3-L5 work needs mode-specific closure and targeted gates for a selected authorization, abuse, secret, dependency, privacy, cloud, AI, or tool-authority riskA compact L1/L2 result is sufficient and no selected risk needs the extended proof contractAnalysisTaskReview