Skip to content

docs: epic for explicit aidd-security-review skill (mandatory /review pass)#164

Draft
ericelliott wants to merge 4 commits intomainfrom
cursor/openfang-security-review-4266
Draft

docs: epic for explicit aidd-security-review skill (mandatory /review pass)#164
ericelliott wants to merge 4 commits intomainfrom
cursor/openfang-security-review-4266

Conversation

@ericelliott
Copy link
Collaborator

@ericelliott ericelliott commented Mar 21, 2026

Summary

Adds a planned task epic to introduce aidd-security-review: a checklist-driven security skill that /aidd-review must invoke so first-pass reviews catch structural auth/secret failures without relying on OWASP alone.

Epic file

  • tasks/aidd-review-explicit-security-skill-epic.md

Updates

  • Overview reframed around least knowledge, least privilege, security in layers, and prefer the safer option (explicit Principles section).
  • Removed condescending / leading phrasing about “absolutist fiction.”
  • Author task now requires the new skill to open with that Principles block.

Follow-up work (in the epic)

  • New .cursor/skills/aidd-security-review/SKILL.md with explicit checklist + principles.
  • Wire into aidd-review (.cursor + ai/skills copies).
  • References with bad/good pattern pairs.
  • Cross-links from AGENTS.md / agent entry points.

This PR tracks the epic document; implementation is subsequent tasks per the epic.

Open in Web Open in Cursor 

cursoragent and others added 4 commits March 21, 2026 16:24
Co-authored-by: Eric Elliott <support@paralleldrive.com>
…g prose

Co-authored-by: Eric Elliott <support@paralleldrive.com>
Co-authored-by: Eric Elliott <support@paralleldrive.com>
…d checklist)

Co-authored-by: Eric Elliott <support@paralleldrive.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants