mcaf-security-baseline

Apply baseline security guidance to code and infrastructure changes.

4|Updated Mar 6, 2026
One-click install
npx skills add https://github.com/managedcode/MCPGateway --skill mcaf-security-baseline
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: mcaf-security-baseline
Source: https://github.com/managedcode/MCPGateway/tree/main/.codex/skills/mcaf-security-baseline
Command: npx skills add https://github.com/managedcode/MCPGateway --skill mcaf-security-baseline

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill helps teams apply essential security guidance to their code and infrastructure, ensuring secure defaults, proper secrets handling, and thorough threat modeling for changes with security implications.

Core Features & Use Cases

  • Security Guidance: Provides baseline security best practices for secrets management, authentication, data flow, and pipelines.
  • Threat Modeling References: Offers structured questions and outputs for identifying and mitigating potential security risks.
  • Use Case: When introducing a new API endpoint that handles user data, use this Skill to review authentication, authorization, and data handling to ensure it adheres to security baselines.

Quick Start

Run this skill's workflow to identify and address security concerns for a new feature.

Frequently Asked Questions about mcaf-security-baseline

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I apply security baseline checks for new API endpoints handling user data?

Threat modeling for infrastructure changes involves structured questions to identify and mitigate security risks in data flow and external integrations. This Skill outputs risk assessments to guide mitigation strategies across pipelines.

What is the best way to review secrets management in code and infrastructure changes?

Reviewing secrets management in code requires applying baseline security engineering guidance to ensure proper handling. This Skill provides reference workflows to assess and mitigate risks related to secrets in pipeline deployments.

How do I set up threat modeling checkpoints for pipeline security and external integrations?

Setting up threat modeling checkpoints for pipeline security involves utilizing structured workflows to assess external integrations and data flow. This Skill establishes review checkpoints to mitigate risks during code and infrastructure changes.

Does this security baseline guidance work without external dependencies?

Yes, this security baseline guidance works without external dependencies, utilizing internal security references to apply secure defaults. It is designed to fit seamlessly into existing code review and risk assessment workflows.

When do I need to use secure defaults for authentication and data flow?

You need to use secure defaults for authentication and data flow when introducing code or infrastructure changes with security implications. This Skill helps enforce these baselines to mitigate risks in external integrations and pipelines.