secure-ship

Run pre-deploy security reviews across nine domains with automated scanners.

Updated Jun 8, 2026
One-click install
npx skills add https://github.com/QuestionPilot/authored-skills --skill secure-ship
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: secure-ship
Source: https://github.com/QuestionPilot/authored-skills/tree/main/skills/secure-ship
Command: npx skills add https://github.com/QuestionPilot/authored-skills --skill secure-ship

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill provides a comprehensive pre-deploy secure-development review for code changes, ensuring changes are safe to merge and deploy.

Core Features & Use Cases

  • 9-Domain Methodology: Walks a 9-domain methodology (SAST, dependencies, secrets, CI/CD, containers, IaC, API/web, crypto, threat modeling).
  • Automated Scanners: Runs matching OSS scanners for each domain.
  • Risk-Rated Checklist: Applies a risk-rated checklist and emits a ship/fixed/no-ship gate.
  • Use Case: Before merging a code change, use this Skill to scan for vulnerabilities and ensure compliance with security standards.

Quick Start

Run the secure-ship skill on your code changes before merging.

Frequently Asked Questions about secure-ship

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is a pre-deploy secure-development review for code changes?

A pre-deploy secure-development review scans code changes across 9 domains—SAST, dependencies, secrets, CI/CD, containers, IaC, API/web, crypto, and threat modeling—using manual checklists and automated scanners to ensure safe deployment.

How do I run a security compliance check before merging code changes?

To run a security compliance check before merging, execute a pre-deploy review that applies a risk-rated checklist across 9 security domains and runs matching automated scanners to emit a ship, fixed, or no-ship gate decision.

Can I use automated vulnerability scanning for CI/CD and containers before deployment?

Yes, automated vulnerability scanning for CI/CD and containers is supported as part of a 9-domain pre-deploy review, running matching open-source scanners for each domain alongside a manual checklist to gate deployments.

What's the best way to perform threat modeling and secrets scanning for infrastructure as code?

The best way to perform threat modeling and secrets scanning for infrastructure as code is using a comprehensive pre-deploy review methodology that applies risk-rated checklists and automated scanners across 9 distinct security domains.

Does this pre-deploy review support SAST and dependency scanning for API and web applications?

Yes, this pre-deploy review supports SAST and dependency scanning for API and web applications, running automated open-source scanners and manual checklists across 9 domains including crypto and threat modeling to produce a deployment gate.

When do I need a risk-rated checklist and automated scanner for secure code deployment?

You need a risk-rated checklist and automated scanner for secure code deployment when you want to enforce a ship, fixed, or no-ship gate decision across 9 security domains before merging any code changes into production.