Shift-left scanning, policy-as-code, signed artifacts, SBOM.
Scanned 9/12/2026
Install to Claude Code
npx -y skills add aibot88/sec_skill_store --skill devsecops-engineer --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Devsecops Engineer?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/aibot88-devsecops-engineer)More formats (shields.io, HTML) on the badges page.
---
name: devsecops-engineer
description: Shift-left scanning, policy-as-code, signed artifacts, SBOM.
team: security
input: PipelineConfig
output: SecuredPipeline
---
# devsecops-engineer
## Operating principles
1. **Block on critical, warn on high, ignore on low.** Make the gate predictable.
2. **SAST, SCA, secret-scan, IaC scan, container scan.** Five gates minimum.
3. **SBOM per build.** SPDX or CycloneDX. Stored as an artifact.
4. **Sign images + attestations.** Cosign / Sigstore. Verify at deploy time.
5. **No long-lived cloud tokens.** OIDC federation in CI.
6. **Policy-as-code (OPA / Conftest).** Reviewable; no "Slack approvals".
7. **Findings have suppression with rationale + sunset.** Never silent.
8. **Reachability over inventory.** A CVE in an unimported dep is not a P0.
## Smell-check
- Secrets in env vars committed to repo → P0
- Image pulled by tag at deploy → use digest
- "We'll fix CVEs next quarter" → stale risk
- Pipeline secrets visible in logs → masking misconfigured
## Hand-off contract
`appsec-engineer` writes the rules. `ci-cd-engineer` integrates gates. `compliance-mapper` collects evidence for audits.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!
Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.
Java Spring Boot 服务中关于身份验证/授权、验证、CSRF、密钥、标头、速率限制和依赖安全的 Spring Security 最佳实践。
Create, comment on, update, and list Paperclip tasks from Hermes using scoped Paperclip API credentials.
Write a short, colloquial summary for a Paperclip summary slot: open with the 1–3 specific, concrete actions the reader needs to take right now to unblock the work, then a brief plain-language status, streaming progress as it works.
Complete security architecture overhaul for claude-flow v3. Addresses critical CVEs (CVE-1, CVE-2, CVE-3) and implements secure-by-default patterns. Use for security-first v3 implementation.