Jordan’s Toolkit
GitHub
← All roles

SPECIALIST PRESET · REVIEW · V0.1.0

Security Reviewer

Review trust, tenant and execution boundaries using concrete data flows and authorized negative tests.

Guidance, not a worker. This experimental preset selects skills. It does not launch an agent, establish expertise or grant permissions. Requested mode: read-only; the host must enforce the actual policy.
Inspect the role selection

From a full checkout. JSON includes file hashes, not an installation or an execution.

node tools/bundle.mjs role security-reviewer
Read role registry ↗

Expected handoff

  • Evidence-linked trust-boundary findings
  • Scoped remediation options and remaining uncertainty

Bring this context

  • Threat assumptions, identities and tool effects
  • Authorized disposable negative-test environment

Keep out of scope

  • Do not attack unapproved systems or expose secrets
  • Do not equate a checklist with security certification

Choose the procedure the task needs.

These 5 skills are references, not instructions to load everything at once.

Original

Tenant Authorization Boundaries

Enforce tenant-scoped operations across transports, jobs, data, and caches using trusted identity and independent cross-tenant denial tests.

Security and stateexperimental
Original

Frontend Security Boundaries

Keep untrusted content, navigation, credentials and server effects behind explicit boundaries while testing the real browser-to-server trust model.

Securityexperimental
Original

MCP Server Qualification

Qualify a specific third-party MCP server revision through identity, effect review and actual protocol/operation evidence rather than treating discovery as approval.

MCP and bundlesexperimental
Original

Agent Permission Delegation

Reduce child-agent authority to the intersection of parent authority, task needs, organization policy, and currently approved effects.

Agent runtimeexperimental
Original

Build Cache Trust

Review producer/consumer cache authority, scoped credentials, sensitive output, nonproduction denial tests, and recovery from suspect artifacts.

Infrastructureexperimental

A private binding, not a fork.

The execution environment supplies real roots, contracts, account context, budgets, tool access and independent acceptance. Keep those private. Review or analysis mode does not itself block a shell command; the host must do that.

Explore Specialist Role Composition →