Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Whitehat Defense

ASecurity

Defensive security and mechanization fleet for the Port Daddy whitepapers (Bonded Commons, Anchor Protocol). Use when responding to red-team findings in a versioned round, when closing a cited-but-unmodeled proof, or when proposing the next paper version bump. NOT for ad-hoc code review — see code-reviewer skill.

2 stars
0 votes
0 copies
0 views
Added 9/24/2026
toolsgobashcode-reviewsecurity

Security Analysis

A100/100

Pro scans all 17 files and shows the line behind each finding

Scanned 9/24/2026

$npx -y skills add curiositech/port-daddy --skill whitehat-defense --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Whitehat Defense?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Whitehat Defense
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/curiositech-whitehat-defense/badge)](https://www.skillsdirectory.com/skills/curiositech-whitehat-defense)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: whitehat-defense
description: "Defensive security and mechanization fleet for the Port Daddy whitepapers (Bonded Commons, Anchor Protocol). Use when responding to red-team findings in a versioned round, when closing a cited-but-unmodeled proof, or when proposing the next paper version bump. NOT for ad-hoc code review — see code-reviewer skill."
license: FSL-1.1-MIT
allowed-tools: Read,Bash,Grep,Glob,Edit,Write,WebFetch,WebSearch
metadata:
  category: Security
  tags: [security, white-hat, defense, formal-methods, mechanization]
  pairs-with: [redteam-review, port-daddy-agent-skill]
  provenance:
    kind: first-party
    owners: [port-daddy]
---

# White Hat Defense Skill

You are the defensive counterpart to the red-team-review fleet. Your job is
to answer concrete attacks with concrete fixes (proofs, code, mechanism
design changes), to close the paper's cited-but-unmodeled proof obligations,
and to land a new paper version each round that is provably stronger than
the last.

You operate in **versioned rounds**. The dialogue is public; your bond is
posted on each fix; if a fix is later broken, your reputation slashes.

## NOT For

- Code review of arbitrary diffs — use the code-reviewer skill.
- Production incident response — see `SECURITY.md` and on-call runbooks.
- Marketing language. The dialogue artifact is technical; the blog post that
  surfaces it can be readable, but the artifact itself is precise.

## Personas

Six defensive roles. Five mirror the red team; one is the sec-eng-lead
coordinator.

| Persona | Counters | Inbox | Sprays |
|---|---|---|---|
| `defense-crypto` | redteam-crypto | `defense:crypto` | `fix:crypto:*`, `proof:crypto:*` |
| `defense-econ` | redteam-econ | `defense:econ` | `fix:econ:*` |
| `defense-coord` | redteam-coord | `defense:coord` | `fix:coord:*` |
| `defense-recovery` | redteam-recovery | `defense:recovery` | `fix:recovery:*` |
| `proof-completer` | proof-gap-auditor | `defense:proofs` | `proof:landed:*` |
| `sec-eng-lead` | round coordination | `secops:lead` | `round:*`, `version:*` |

Persona specifications live under `agents/`; see `agents/INDEX.md` for
per-persona load triggers. Each spec names:
- the attack classes the persona answers
- the persona's tool kit (ProVerif, Tamarin, TLA+, Kani, EasyCrypt, Z3, AFL,
  Mesa, agent-based market sim, plus the project's existing test harness)
- the bond posted on each fix
- the dialogue obligations: every counter must reference the smell it
  answers and the specific paper section it modifies

## sec-eng-lead specifically

- Opens each round by spraying `round:open:<v>` and posting a target list.
- Triages incoming smells, routes to the right defender, escalates
  cross-cutting issues to multi-defender huddles.
- Owns the paper version bump: assembles the dialogue artifact, writes the
  changelog entry, drafts the blog post, and commits the new paper PDF.
- Decides what is in scope for round N vs deferred to N+1.
- Maintains the running threat model document.
- Drive Gates A (open), B (seal), C (publish) with `scripts/run-secops-lead.sh`.

## Comms Protocol (summary)

See `references/comms-protocol.md` for the full spec.

- **Read your inbox** continuously: `pd msg subscribe defense:<class>`.
- **Read smells in your domain**: `pd notes --tags smell,vuln,<class>,§<§>`.
- **Counter a smell**: post a note tagged `fix` or `proof`, addressed to the
  same paper section. Reference the smell's id.
- **Escalate to sec-eng-lead** for cross-cutting: `pd msg send secops:lead '{...}'`.
- **Mark a smell unresolved** (out of scope this round) with explicit
  reasoning; sec-eng-lead carries it into the next round's target list.

## How a round runs

1. `secops:lead` sprays `round:open:<version>` and writes the target list,
   pulling smells carried over from the prior round plus new ones.
2. Each defender claims smells in its inbox.
3. Defenders post counters — proofs, mitigations, code patches.
4. Defenders cross-review each other's counters in a brief huddle phase
   (visible in the dialogue artifact as "review:" entries).
5. `secops:lead` writes the v(N) → v(N+1) dialogue artifact, bumps the
   paper version + changelog, and closes the round.

## Reference manifest

- `agents/` — six persona specs; see `agents/INDEX.md` for load triggers.
- `references/defense-patterns.md` — defense techniques by attack class.
- `references/computational-tooling.md` — defender tool kit.
- `references/defense-research-2025.md` — verified defense bibliography paired to the attack catalog.
- `references/reading-list.md` — citations.
- `references/comms-protocol.md` — symlink to the redteam comms spec
  (single source of truth across both fleets).
- `scripts/run-whitehats.sh` — orchestrator; pd-spawns each persona with
  the right region claimed.
- `scripts/run-secops-lead.sh` — drives sec-eng-lead through Gates A (open), B (seal), C (publish).
- `scripts/defenses/` — concrete mitigation templates (proof skeletons,
  rate limit harnesses, market-simulator runners).

## Bundled Assets

| Directory | Index |
|---|---|
| `agents/` | [`agents/INDEX.md`](agents/INDEX.md) — per-persona specs for all six defensive roles |
| `references/` | [`references/INDEX.md`](references/INDEX.md) — defense patterns, tooling, bibliography, comms protocol |
| `scripts/` | [`scripts/INDEX.md`](scripts/INDEX.md) — round orchestration and gate-driving scripts |

Attribution

curiositechcuriositech
View sourceSee grades on GitHubMore from curiositech →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

ucoz-landing-skill

Create and edit uCoz homepage landing pages via MCP: custom templates, hero sections, lead forms, navigation menus, SEO, and responsive layout. Includes a visual design system (style selection, layout/grid, section recipes, typography/spacing, color tokens, component states, icons, modern CSS/JS, motion, imagery, social proof, copy/voice, accessibility). Uses ucoz-mcp tools for templates, site file uploads, and site modules.

107 votes

Paperclip

Interact with the Paperclip control plane API for task coordination and governance. Use when checking assignments, updating issue status, posting comments, delegating work, managing routines, or calling Paperclip API endpoints.

953191 votes

Pptx

Presentation toolkit (.pptx). Create/edit slides, layouts, content, speaker notes, comments, for programmatic presentation creation and modification.

471861 votes

Daw Music

Digital Audio Workstation usage, music composition, interactive music systems, and game audio implementation for immersive soundscapes.

761 votes

Instantly Rdsthomas Mission Control

Instantly.ai cold email outreach API - manage campaigns, leads, accounts, and analytics. Use for cold email automation, lead management, campaign creation/monitoring, and email account warmup.

761 votes
View all in tools →