All skills
web-security
FoundationJIT onlyUse analysis, task, or review agents for reachable web-sink changes; skip without web exposure.
- Group
- Security & privacy
- Supported roles
- MainAnalysisTaskReview
- Source
- SKILL.md
Use when
Trigger signals that make this skill the right owner
- review changed web routes from browser or server trust boundary to rendering state-changing fetch upload redirect cross-origin embedding or protected-action sinks
Do not use when
Anti-triggers — as binding as the triggers above
- no task-local reachable web boundary or sink behavior changes
Required inputs
What must be supplied before this skill can decide anything
- current task contract
- selected primary Professional Skill
- task-local trigger evidence
Output contract
What this skill owes the next role
- web-security decision with reachable sources and sinks, contextual controls, state-change integrity, fetch and upload boundaries, cross-origin behavior, denial and bypass evidence, and proof limits
Escalation signals
When this skill must hand the decision back
- Web sink context, browser request authority, fetch resolution or egress, upload publication, effective response policy, permission handoff, or residual ownership remains ambiguous
Loaded by
This skill never owns a task. These professionals may pull it in as Layer 3.
Targeted references
Each reference carries its own load condition. None of them enter context by default.
| Reference | Load when | Do not load when | Required by |
|---|---|---|---|
| benchmarks-and-patterns.mdbenchmark-pattern | competing render browser-state fetch upload navigation cross-origin embedding response-policy or protected-route patterns remain viable | one bounded web decision is already complete from the root contract | AnalysisTaskReview |
| checklist.mddecision-checklist | several reachable web surfaces and their handoffs must close together | one bounded web surface is already complete from the root contract | AnalysisTaskReview |
| evidence-patterns.mdevidence-pattern | route reachability control placement framework behavior denial bypass deployment or residual-scope claims need fresh proof | no task-local web-security claim awaits proof | AnalysisTaskReview |