Shipped-Artifact Security Baseline
skill · reused
Evidence record
- What is verified
- Uses in published workflows: 1
- Revision
- Version 0.1.5
- Validation status
- Public-sanitized publication; no independent validation is claimed.
What this is and why
The canonical security floor for shipped artifacts: eleven rule clusters covering shell and Python hygiene, secrets, supply chain, documentation treated as code, repo hygiene, CI gating, drift response, a branch-integration floor, and an untrusted-content boundary gate. Each cluster is enforced by a required CI job that blocks merge; boundaries where untrusted bytes reach a model also require a distinct adversarial review, since green CI cannot model prompt injection. Every suppression is registered with reason, expiry, and reviewer.
Where it was applied and what it helped deliver
Metadata and provenance
- id
- datarim-skill-security-baseline
- type
- skill
- version
- 0.1.5
- origin
- created in Arcanada
- lifecycle
- public_sanitized
- tags
- skill, talo-0029
The source is the private knowledge repository; only the sanitized public projection reaches this site.
verified · datarim-skill-security-baseline · v0.1.5