securability-engineering-review

Quantify codebase securability with weighted 0–10 pillar scores.

Updated Mar 24, 2023
One-click install
npx skills add https://github.com/j4hr3n/dotfiles --skill securability-engineering-review-j4hr3n
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: securability-engineering-review
Source: https://github.com/j4hr3n/dotfiles/tree/main/configs/claude-code/skills/securability-engineering-review
Command: npx skills add https://github.com/j4hr3n/dotfiles --skill securability-engineering-review-j4hr3n

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Identify and quantify securability attributes in codebases to guide secure maintenance and evolution.

Core Features & Use Cases

  • Evaluates analyzability, modifiability, and testability alongside confidentiality, accountability, and authenticity.
  • Guides code reviews, merge request assessments, and baseline security postures across development teams.
  • Provides a structured scoring rubric and actionable remediation guidance to improve long-term securability.

Quick Start

Run a securability-engineering-review on your codebase following the playbooks and scoring rubric.

Frequently Asked Questions about securability-engineering-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is securability engineering and how does it differ from standard security review?

Securability engineering evaluates maintainability attributes like analyzability, modifiability, and testability alongside security pillars such as confidentiality and accountability, providing a structured 0–10 scoring rubric to guide secure codebase evolution rather than just finding vulnerabilities.

How do I assess code securability for a merge request assessment?

Run a securability-engineering review on your codebase using the structured multi-pillar scoring methodology, evaluating sub-attributes on a 0–10 scale to generate weighted pillar scores and a final grade that quantifies secure maintenance posture for the merge request.

Can I use this securability scoring rubric to establish a baseline security posture across development teams?

Yes, the structured SSEM scoring rubric evaluates codebases against consistent securability attributes, producing weighted pillar scores and a final grade to establish baseline security postures across multiple development teams for long-term maintainability.

Does securability analysis require external code-analysis tools or OWASP dependencies?

No external dependencies are required. The securability-engineering review operates as a standalone playbook and scoring rubric, evaluating code attributes directly to produce actionable remediation guidance without needing specific OWASP or code-analysis tool integrations.

What is the best way to get actionable remediation guidance from a securability engineering review?

Apply the multi-pillar scoring methodology to generate 0–10 sub-attribute scores across analyzability, modifiability, testability, confidentiality, accountability, and authenticity, yielding weighted pillar scores and a final grade with structured remediation guidance.