Shipped-Artifact Security Baseline

skill · reused

Evidence record

What is verified
Uses in published workflows: 1
Source
Published workflow connections
Revision
Version 0.1.5
Validation status
Public-sanitized publication; no independent validation is claimed.

What this is and why

The canonical security floor for shipped artifacts: eleven rule clusters covering shell and Python hygiene, secrets, supply chain, documentation treated as code, repo hygiene, CI gating, drift response, a branch-integration floor, and an untrusted-content boundary gate. Each cluster is enforced by a required CI job that blocks merge; boundaries where untrusted bytes reach a model also require a distinct adversarial review, since green CI cannot model prompt injection. Every suppression is registered with reason, expiry, and reviewer.

Metadata and provenance

id
datarim-skill-security-baseline
type
skill
version
0.1.5
origin
created in Arcanada
lifecycle
public_sanitized
tags
skill, talo-0029

The source is the private knowledge repository; only the sanitized public projection reaches this site.

verified · datarim-skill-security-baseline · v0.1.5