Security Architect Skill
Scanned 9/8/2026
Install to Claude Code
npx -y skills add agisota/old-one --skill security-architect --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Security Architect?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/agisota-security-architect)More formats (shields.io, HTML) on the badges page.
---
triggers:
- "security architect"
name: security-architect
description: Security Architect Skill
---
## The Four Phases
You MUST complete each phase before proceeding to the next.
### Phase 1: Authentication Architecture (The Handshake)
**BEFORE writing a single line of auth code:**
1. **Select the Flow**
- **Mobile/SPA:** MUST use **Authorization Code Flow with PKCE** (Proof Key for Code Exchange).
- **Backend:** Authorization Code Flow.
- **Implicit Flow:** **FORBIDDEN.** Never use it. It returns tokens in the URL.
- **Device Flow:** Only for input-constrained devices (TVs/IoT).
2. **Scope Strategy (Least Privilege)**
- Define exactly which permissions are needed from YouTube (`youtube.readonly`) vs Twitch (`chat:read`).
- **Incremental Auth:** Do not ask for all scopes at signup. Ask for `youtube.upload` only when the user actually clicks "Upload."
- **Justification:** Be ready to explain to the user *why* you need this access.
3. **The "No-Credential" Rule**
- **Principle:** We never see, touch, or store the user's password.
- **Identity Provider (IdP):** Delegate login to the provider (Google/Twitch).
- **Redirect URIs:** strict allow-listing. No wildcards (`*`).
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!
Java Spring Boot 服务中关于身份验证/授权、验证、CSRF、密钥、标头、速率限制和依赖安全的 Spring Security 最佳实践。
Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.
Create, comment on, update, and list Paperclip tasks from Hermes using scoped Paperclip API credentials.
Write a short, colloquial summary for a Paperclip summary slot: open with the 1–3 specific, concrete actions the reader needs to take right now to unblock the work, then a brief plain-language status, streaming progress as it works.
Complete security architecture overhaul for claude-flow v3. Addresses critical CVEs (CVE-1, CVE-2, CVE-3) and implements secure-by-default patterns. Use for security-first v3 implementation.