skill
security-architecture
Optional, opt-in STRIDE threat pass for a sensitive feature — invoked deliberately via /threat-model, never forced on ordinary changes. Walks the change's attack surface and security boundaries (governed by {{PROJECT_DIR}}/.codearbiter/security-controls.md), surfaces threats and unmitigated gaps, and MAY dispatch security-reviewer or auth-crypto-reviewer. Not a routine gate; it can hard-STOP only on a genuinely critical unmitigated threat it surfaces.
Description as published by the maintainer. Source
- active
active — Most recent push to the repository was 2026-08-06.
Signals
These are separate measurements of different things. They are deliberately not combined into one score, because a popularity number that mixes website traffic with saves and stars cannot be checked or acted on.
| Signal | Value | What it measures | Window | Observed | Source |
|---|---|---|---|---|---|
| GitHub stars | 139 | Stars on the repository that contains this skill, not on the skill itself. A collection of fifty skills shares one number, so it says nothing about this particular skill. | cumulative, all time | GitHub | |
| Last commit | 2026-08-06 | Most recent push to the containing repository. It may reflect work on a different skill in the same collection. | point in time | GitHub | |
| repository status | active | The repository holding this skill exists and is not archived. | as of fetch | GitHub |
Will this work with your setup?
Install location suggests this is meant for claude-code. The author tagged this repository "claude-code-skills" on GitHub. That is their statement of intent, not a test result.
We have not run this skill against a task with and without it enabled, so we cannot tell you whether it improves anything, what it costs in tokens, or whether it duplicates behaviour your harness already has. When we have run that test, the result will appear on this page with the task, the versions and the budget it used.
The skill definition lives at core/surface/skills/security-architecture/SKILL.md in https://github.com/arbiterForge/codeArbiter.
Where to get it
Related, by what their authors tagged them
-
arbiterforge-codearbiter-brainstorming
— last commit 2026-08-06, shares ai-coding, ai-safety, chatgpt
The Socratic spec-refinement front of /feature, and the planning front of /sprint. Routed to BEFORE any code — it takes…
-
arbiterforge-codearbiter-brainstorming-6e7b5a
— last commit 2026-08-06, shares ai-coding, ai-safety, chatgpt
The Socratic spec-refinement front of /feature, and the planning front of /sprint. Routed to BEFORE any code — it takes…
-
arbiterforge-codearbiter-commit-gate
— last commit 2026-08-06, shares ai-coding, ai-safety, chatgpt
The only path to a commit. Routed to when the user invokes /commit or otherwise instructs codeArbiter to persist staged…
-
arbiterforge-codearbiter-commit-gate-f32571
— last commit 2026-08-06, shares ai-coding, ai-safety, chatgpt
The only path to a commit. Routed to when the user invokes /commit or otherwise instructs codeArbiter to persist staged…
-
arbiterforge-codearbiter-context-check
— last commit 2026-08-06, shares ai-coding, ai-safety, chatgpt
Optional manual drift audit — report stale provenance-tracked docs (via _provenancelib drift detection across .codearbi…
-
arbiterforge-codearbiter-context-check-becf68
— last commit 2026-08-06, shares ai-coding, ai-safety, chatgpt
Optional manual drift audit — report stale provenance-tracked docs (via _provenancelib drift detection across .codearbi…
-
arbiterforge-codearbiter-context-creation
— last commit 2026-08-06, shares ai-coding, ai-safety, chatgpt
The brownfield back-fill. Routed to by /create-context, and by startup when .codearbiter/CONTEXT.md lacks the <!--INITI…
-
arbiterforge-codearbiter-context-creation-e0181e
— last commit 2026-08-06, shares ai-coding, ai-safety, chatgpt
The brownfield back-fill. Routed to by /create-context, and by startup when .codearbiter/CONTEXT.md lacks the <!--INITI…
-
arbiterforge-codearbiter-crypto-compliance
— last commit 2026-08-06, shares ai-coding, ai-safety, chatgpt
The banned-primitive gate. Routed to when changed code hashes, signs, encrypts, derives keys, generates security-releva…
-
arbiterforge-codearbiter-crypto-compliance-a308c9
— last commit 2026-08-06, shares ai-coding, ai-safety, chatgpt
The banned-primitive gate. Routed to when changed code hashes, signs, encrypts, derives keys, generates security-releva…
These share tags the maintainers applied themselves, such as ai-coding, ai-safety, chatgpt, claude-code-plugin. Common tags like "mcp" or "ai" are ignored for this: agreeing with six hundred other projects is not a similarity.
This is not a recommendation and not a test result. It is a map of what the authors said their work is about.
Also from arbiterforge
-
arbiterforge-codearbiter-debug
— last commit 2026-08-06
Investigate-then-decide root-cause analysis for a defect whose cause is unknown (distinct from /fix, which assumes a kn…
-
arbiterforge-codearbiter-debug-f9b568
— last commit 2026-08-06
Investigate-then-decide root-cause analysis for a defect whose cause is unknown (distinct from /fix, which assumes a kn…
-
arbiterforge-codearbiter-decision-lifecycle
— last commit 2026-08-06
Author and track Architecture Decision Records. Routed to when the user invokes /adr to record a new decision or /adr-s…
-
arbiterforge-codearbiter-decision-lifecycle-df7224
— last commit 2026-08-06
Author and track Architecture Decision Records. Routed to when the user invokes /adr to record a new decision or /adr-s…
-
arbiterforge-codearbiter-decision-variance
— last commit 2026-08-06
Reconcile the project's architectural artifacts against the scaffold and prior decisions, then present each variance as…
-
arbiterforge-codearbiter-decompose
— last commit 2026-08-06
The greenfield decomposition interview. Routed to at startup when .codearbiter/CONTEXT.md lacks the <!--INITIALIZED-->…
-
arbiterforge-codearbiter-dispatching-parallel-agents
— last commit 2026-08-06
The parallel fan-out primitive. Routed to by any skill or command that splits work across independent units and dispatc…
-
arbiterforge-codearbiter-executing-plans
— last commit 2026-08-06
The checkpoint coordinator for /feature. Routed to by /feature once a writing-plans plan exists. Groups tasks into batc…
-
arbiterforge-codearbiter-finishing-a-development-branch
— last commit 2026-08-06
The terminal step of /feature and /sprint. Routed to once commit-gate has cleared, to decide the branch's fate — merge…
-
arbiterforge-codearbiter-post-merge-cleanup
— last commit 2026-08-06
Finish an already-merged branch. Proves the branch is contained in the fetched default, classifies leftover artifacts a…
How the author describes it
Topics the maintainer set on GitHub: ai, ai-agents, ai-coding, ai-governance, ai-safety, ai-tools, chatgpt, claude, claude-code, claude-code-plugin, claude-code-skills, claude-plugin, claude-skills, codex, codex-cli, codex-plugin, codex-skill, codex-skills, orchestration, pi.
Bring your own setup
We take apart real AI setups every week and show what broke, what cost too much, and what the trace actually said. If you run agents on real work, that is where the useful conversation is.
Join ZBS AI Practice Lab