Agent Skillsmtarcure/claude-vibe-squad › security-ownership-map

security-ownership-map

GitHub

基于代码、提交和运维记录构建安全组件所有权映射,明确责任人及决策权,识别无主或权限不足组件,确保安全发现能正确路由至可执行修复的人员。

.agents/skills/security-ownership-map/SKILL.md mtarcure/claude-vibe-squad

Trigger Scenarios

安全事件责任不清 安全漏洞无法定责 需要梳理组件所有者

Install

npx skills add mtarcure/claude-vibe-squad --skill security-ownership-map -g -y
More Options

Non-standard path

npx skills add https://github.com/mtarcure/claude-vibe-squad/tree/main/.agents/skills/security-ownership-map -g -y

Use without installing

npx skills use mtarcure/claude-vibe-squad@security-ownership-map

指定 Agent (Claude Code)

npx skills add mtarcure/claude-vibe-squad --skill security-ownership-map -a claude-code -g -y

安装 repo 全部 skill

npx skills add mtarcure/claude-vibe-squad --all -g -y

预览 repo 内 skill

npx skills add mtarcure/claude-vibe-squad --list

SKILL.md

Frontmatter
{
    "name": "security-ownership-map",
    "audience": "specialist",
    "description": "Use when security findings or incident responsibilities are stalling because component ownership and decision rights are unclear—derive an evidence-backed map from code ownership, commit, deploy, and on-call records; record patch, shutdown, and credential-rotation authority; and flag unowned, departed, shared, vendor, or powerless owners. This routes remediation; it is not a system threat model."
}

Security Ownership Map

Establish who owns each security-relevant component, so findings route to someone who can act and no surface is left unowned.

Steps

  1. Enumerate security-relevant components: authentication, authorization, secrets handling, data stores holding sensitive data, external integrations, deployment and CI, and the network edge.
  2. For each component, derive candidate owners from evidence — code ownership files, commit history concentration, deploy configuration, and on-call rotations — rather than from an org chart.
  3. Record for each component: owning team or person, escalation path, and the decision rights they actually hold (can they patch, can they take it offline, can they rotate its credentials).
  4. Flag every component with no owner, a departed owner, or an owner who lacks the rights to remediate. Unowned security surface is itself a finding.
  5. Flag shared-ownership components where responsibility is genuinely ambiguous; these are where findings stall longest.
  6. Map each finding class to the owner who can remediate it, distinguishing the owner of the code from the owner of the deployment where these differ.
  7. Note cross-boundary components — vendor-managed, contractor-built, or inherited — and record the contractual or practical limit on what can be changed.
  8. Date the map and name its evidence sources; ownership decays and an undated map silently misroutes.

Acceptance

  • Every security-relevant component has a named owner, escalation path, and stated decision rights, or is explicitly flagged unowned.
  • Ownership is derived from observable evidence, with the source cited per component.
  • Components whose owner cannot remediate are called out separately from unowned ones.
  • Finding classes are routed to the owner able to act on them.
  • The map carries a date and its evidence sources.

Version History

  • d5262e2 Current 2026-09-11 11:25

Same Skill Collection

.agents/skills/accessible-media-authoring/SKILL.md
.agents/skills/agent-prompt-engineering/SKILL.md
.agents/skills/agentic-safety-audit/SKILL.md
.agents/skills/audio-event-map-authoring/SKILL.md
.agents/skills/auto-scaffold/SKILL.md
.agents/skills/claim-verification/SKILL.md
.agents/skills/code-reachability-audit/SKILL.md
.agents/skills/code-review-loop/SKILL.md
.agents/skills/color-theory/SKILL.md
.agents/skills/conversation-design/SKILL.md
.agents/skills/copy-refinement/SKILL.md
.agents/skills/cross-file-relationship-synthesis/SKILL.md
.agents/skills/dependency-cycle-audit/SKILL.md
.agents/skills/dependency-health-triage/SKILL.md
.agents/skills/detection-as-code/SKILL.md
.agents/skills/diff-aware-semgrep-scan/SKILL.md
.agents/skills/differential-review/SKILL.md
.agents/skills/dimensional-analysis-check/SKILL.md
.agents/skills/dual-level-retrieval/SKILL.md
.agents/skills/figma-implement-design/SKILL.md
.agents/skills/forensic-timeline-authoring/SKILL.md
.agents/skills/game-design-fundamentals/SKILL.md
.agents/skills/game-mechanics-balancing/SKILL.md
.agents/skills/head-tail/SKILL.md
.agents/skills/incident-response-runbook/SKILL.md
.agents/skills/interactive-audio-design/SKILL.md
.agents/skills/interface-ambiguity-check/SKILL.md
.agents/skills/keyword-clustering/SKILL.md
.agents/skills/knowledge-base-integration/SKILL.md
.agents/skills/layered-analysis-loop/SKILL.md
.agents/skills/level-design-patterns/SKILL.md
.agents/skills/locale-adaptation/SKILL.md
.agents/skills/narrative-structure/SKILL.md
.agents/skills/platform-compliance/SKILL.md
.agents/skills/player-engagement-psychology/SKILL.md
.agents/skills/requirements-elicitation/SKILL.md
.agents/skills/rule6-rights-gate/SKILL.md
.agents/skills/rule8-truth-gate/SKILL.md
.agents/skills/sandbox-provision-discipline/SKILL.md
.agents/skills/scope-decomposition/SKILL.md
.agents/skills/scope-estimation/SKILL.md
.agents/skills/security-threat-model/SKILL.md
.agents/skills/semgrep-rule-author/SKILL.md
.agents/skills/skill-description-trigger-authoring/SKILL.md
.agents/skills/sound-design-principles/SKILL.md
.agents/skills/structured-data-authoring/SKILL.md
.agents/skills/supply-chain-audit/SKILL.md
.agents/skills/take-over-resume/SKILL.md
.agents/skills/technical-seo-audit/SKILL.md

Metadata

Files
0
Version
d5262e2
Hash
fa25b100
Indexed
2026-09-11 11:25

Home - Wiki
Copyright © 2011-2026 iteam. Current version is 2.155.2. UTC+08:00, 2026-09-13 05:14
浙ICP备14020137号-1 $Map of visitor$