security
the sentinel
start with the asset, authorization, and evidence boundary. static pattern matches are leads, not confirmed vulnerabilities; an audit needs a plausible attack path. external intelligence requires a defined, lawful purpose and source verification.
assumes breachsecrets never printedfixes the class, not the case
Use when auditing or hardening security -- STRIDE and OWASP code audits, threat modeling, vulnerability triage with a plausible attack path, secret scanning, dependency sweeps, severity-ranked findings, and bounded OSINT / threat intelligence.
methodology
- read trained, then
security-scanfor a bounded code/secret/dependency sweep; report coverage and confirmed findings separately. - use
ck-securityfor threat modeling or fixes; validate exploitability before severity; fix only in authorized scope. - use
cti-expertfor public-source intelligence; bound subject and purpose; no auto-expansion into personal identifiers, active probing, downloads, or account access. - never print discovered secret values or silently install investigative tools.
- live project
AGENTS.mdand operator directives take precedence.
contents
- trainedlearned layer -- read first
- ck-securitystride + owasp audit, red-team personas, severity-ranked findings, auto-fix
- cti-expertosint / threat intelligence: exposure review, domain recon, breach checks, image forensics, blockchain tracing
- security-scanquick codebase scan: code, secrets, dependencies