Security & Compliance skills

Application security, quality management, and compliance review.

Skills in this category

105 skills in this collection

Bitwarden logo

Action Audit

Audit GitHub Actions action usage across an org. Searches for a specific action (incident mode) or sweeps all workflow files for non-compliant action references (audit mode). Produces a read-only report of findings with compliance status…

BitwardenOfficial
Bitwarden logo

Action Remediate

Fix GitHub Actions findings from the action-audit skill, pin external actions to full commit SHAs, and create draft pull requests.

BitwardenOfficial
Bitwarden logo

Addressing Code Review Comments

Guidance for tasks where the user is addressing pull request review comments locally and asks for help evaluating, implementing, or drafting responses to reviewer feedback - requires technical rigor and verification, not performative…

BitwardenOfficial
Bitwarden logo

Analyzing Code Security

This skill should be used when the user asks to "analyze code for security issues", "check for OWASP vulnerabilities", "review code against CWE Top 25", "find injection vulnerabilities", "do a security code review", or needs manual…

BitwardenOfficial
Bitwarden logo

Analyzing Git Sessions

Analyzes git commits and changes within a timeframe or commit range, providing structured summaries for code review, retrospectives, work logs, or session documentation.

BitwardenOfficial
Bitwarden logo

Applying Bitwarden Branding

Apply Bitwarden brand standards — logo usage, color palette, typography, iconography, and capitalization rules — grounded in bitwarden.com/brand and the bitwarden/brand repository.

BitwardenOfficial
Bitwarden logo

Applying Pr Conventions

Compose the conventions a Bitwarden pull request needs — the conventional commit type prefix and title, the repo's PR template body, and the ai-review label. Use for "what should the PR title be", "draft the PR body", "fill in the PR…

BitwardenOfficial
Bitwarden logo

Architecting Solutions

Architecting solutions at the team level while staying coherent with Bitwarden's holistic architecture. Covers security mindset, architectural judgment, Bitwarden-specific constraints, and working with the architecture group.

BitwardenOfficial
Bitwarden logo

Assessing Jira Issue Relevance

Guidance for tasks where the user provides a single Jira issue key and asks whether it is still relevant, still applicable, still pending, still a bug, has been fixed, or can be closed. Trigger phrases include "Is [TICKET] still…

BitwardenOfficial
Bitwarden logo

Assessing Test Coverage

Guidance for tasks where determining what test coverage ALREADY exists for a specific change (a PR, Jira key, Tech Breakdown doc, Testmo CSV, changed paths, or named component). Triggers on "what's already tested", "does this PR have…

BitwardenOfficial
Bitwarden logo

Auditing External Claude Plugins

Audits an external (third-party) Claude Code plugin pinned in this marketplace for security risk before it is vendored, and writes the report to a file for downstream posting.

BitwardenOfficial
Bitwarden logo

Auditing Workflow Conventions

Reference for Bitwarden GitHub Actions naming conventions that the workflow linter (bwwl) does not enforce. Covers three standards — job IDs (kebab-case), step names (Sentence case imperative), and workflow file names (kebab-case.yml…

BitwardenOfficial
Auth0 logo

Auth0

Guidance for adding, fixing, or improving how an app authenticates users or protects an API, or when using or configuring any Auth0 feature — signing users in and out, sessions and tokens, guarding routes and endpoints, MFA, passwordless…

Auth0Official
Bitwarden logo

Avoiding False Positives

Use this skill to validate findings during a code review. For each finding, run the rejection criteria and verification checks. If a finding fails any check, drop it. In PR mode it also holds the once-per-review stacked-PR gate that…

BitwardenOfficial
Microsoft logo

Azure Identity for Python

Azure Identity SDK for Python authentication with Microsoft Entra ID. Use for DefaultAzureCredential, managed identity, service principals, and token caching.

MicrosoftOfficial
Bitwarden logo

Bitwarden Security Context

Bitwarden's security principles (P01-P06), security vocabulary, and data classification standards.

BitwardenOfficial
Bitwarden logo

Bitwarden Workflow Linter Rules

Reference for all Bitwarden workflow linter (bwwl) rules. Covers all 10 linter rules split into two categories: mechanical rules that can be applied automatically (namecapitalized, permissionsexist, pinnedjobrunner, steppinned…

BitwardenOfficial
Bitwarden logo

Championing A Strategy Idea

Primary-Owner playbook for shepherding a Technical Strategy Idea through Architecture's pre-funnel evaluation into the Software Initiative Funnel.

BitwardenOfficial
Bitwarden logo

Classifying Review Findings

Guidance for tasks where categorizing code review findings into severity levels. Apply when determining which emoji and label to use for PR comments, deciding if an issue should be flagged at all, or classifying findings as CRITICAL…

BitwardenOfficial
Bitwarden logo

Committing Changes

Git commit conventions and workflow for Bitwarden repositories.

BitwardenOfficial

20 of 105 skills loaded

Agent skills FAQ

An agent skill is a folder of instructions, usually headed by a SKILL.md file, that helps an AI assistant perform a specific task. A skill may also include scripts, examples, and reference files.