General-purpose coding policy for Baruch's AI agents
73
92%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Low
Low-risk findings worth noting
Use when the task changes a trust boundary or creates a concrete security question, such as who may perform an action or where untrusted input reaches a sensitive operation. Scope the work to the affected behavior and actual threat.
Supply the relevant data flow, assets, actors, trust boundaries and accepted requirements. State the authorized environment and permitted inspection or test actions. Name available source analysis and test tools or a relevant installed security skill. Do not infer testing authority for external systems from access to their credentials or URLs.
Return the bounded threat assessment, findings tied to code or behavior, prerequisites, impact, and targeted corrections or verification. Use sanitized evidence; never place secrets or sensitive payloads in a report. State tools, coverage and uncertainty. A clean focused report establishes only the checked scope, not whole-system security.
Record any security design or implementation you contributed. Recommend durable trust-boundary lessons through the lead's existing memory workflow.
.tessl-plugin
hooks
rules
skills
adopt-fork-pr
herdr-standup
herdr-teamlead
references
teamlead
templates
tests
migrate-to-plugin
onboard-repo
release
tests