security-baseline

Codify OWASP Top 10 and supply chain security rules for multi-agent SSDLC workflows.

Updated Apr 4, 2026
One-click install
npx skills add https://github.com/hiiamsky/multi-agent-dev-team --skill security-baseline-hiiamsky
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-baseline
Source: https://github.com/hiiamsky/multi-agent-dev-team/tree/main/.github/skills/security-baseline
Command: npx skills add https://github.com/hiiamsky/multi-agent-dev-team --skill security-baseline-hiiamsky

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

The security baseline provides a universal SSDLC framework for multi-agent development teams to ensure consistent, auditable security practices across all stages of software delivery.

Core Features & Use Cases

  • Centralized rules referencing OWASP Top 10: Web App 2025, API 2023, LLM 2025, plus supply chain tooling and PDPA compliance.
  • Applies during implementation, cross-domain reviews, and QA/QC security verification to enforce uniform security standards across Orchestrator, SA/SD, PGs, DBA, QA/QC, and E2E teams.
  • Enables loading and applying security rules to agent blueprints and feature specifications to guide design and reviews.

Quick Start

Load the security baseline into the active context and apply it during development, cross-domain reviews, and QA/QC security checks.

Frequently Asked Questions about security-baseline

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I enforce OWASP compliance across a multi-agent SDLC?

You can enforce OWASP compliance by loading a centralized security baseline into the active context, applying codified rules for Web, API, and LLM during implementation, cross-domain reviews, and QA/QC verification.

What is a security baseline in multi-agent software development?

A security baseline is a universal SSDLC framework that ensures consistent, auditable security practices across all stages of software delivery for multi-agent development teams, orchestrators, and QA/QC groups.

How do I apply SSDLC security rules to agent blueprints and feature specifications?

You apply SSDLC security rules by loading the baseline into active context to guide design and reviews, ensuring uniform security standards across SA/SD, PGs, DBA, and E2E teams.

Does the security baseline include software supply chain controls and PDPA compliance?

Yes, the security baseline includes centralized rules referencing software supply chain tooling and PDPA compliance requirements alongside OWASP Top 10 for Web App, API, and LLM.

Can I use this baseline for QA/QC security verification in cross-domain reviews?

Yes, the baseline applies during implementation, cross-domain reviews, and QA/QC security verification to enforce uniform security standards across all multi-agent development teams.

When do I need to load the security baseline into the active context?

You load the security baseline into the active context during development, cross-domain reviews, and QA/QC security checks to apply safety rules to agent blueprints and feature specifications.