speckit-security-review-init

Initialize or refine a project's Security Constitution at `.specify/memory/security_constitution.md`.

Updated Mar 16, 2026
One-click install
npx skills add https://github.com/B0yZ4kr14/OrthoPlus-Enterprise --skill speckit-security-review-init
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: speckit-security-review-init
Source: https://github.com/B0yZ4kr14/OrthoPlus-Enterprise/tree/main/.specify-backups/20260518-141826/_agents/skills/speckit-security-review-init
Command: npx skills add https://github.com/B0yZ4kr14/OrthoPlus-Enterprise --skill speckit-security-review-init

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps you create or refine a single, authoritative Security Constitution so security audits have consistent trust boundaries, authentication standards, and enforceable rules.

Core Features & Use Cases

  • Detects existing security rule files and decides whether to refine, migrate, or start discovery.
  • Runs a Security Discovery Interview to gather trust boundaries, identity and access model, data sensitivity/compliance needs, and secrets/infrastructure requirements.
  • Generates a structured constitution document at .specify/memory/security_constitution.md with enforceable, audit-ready guardrails.

Quick Start

Ask the AI to run speckit-security-review-init to initialize or update .specify/memory/security_constitution.md using your project’s current constitution and security requirements.

Frequently Asked Questions about speckit-security-review-init

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I establish a source of truth for security audits?

To establish a source of truth for security audits, you initialize a Security Constitution document defining trust boundaries, authentication standards, and enforceable rules. This creates an authoritative reference for compliance mapping and security reviews.

What is a Security Constitution and when do I need one for my project?

A Security Constitution is a structured document capturing your project's trust boundaries, identity model, data privacy rules, and secrets policies. You need one to establish baseline standards for consistent security auditing and compliance mapping.

How do I document trust boundaries and secrets management policies for security discovery?

You document trust boundaries and secrets management policies by running a Security Discovery Interview. This process gathers access models, data sensitivity needs, and infrastructure requirements to generate an audit-ready constitution file.

Can I refine an existing security constitution file without losing my current rules?

Yes, you can refine an existing security constitution file without losing current rules. The initialization process detects existing security files and applies non-destructive guardrails during overwrites to preserve your original configurations.

What are the limitations of using a security constitution for compliance mapping?

The limitation of using a security constitution for compliance mapping is its reliance on accurate discovery inputs. If your security discovery interview lacks precise data privacy or authentication details, the generated constitution will contain incomplete audit guardrails.