# Platform Security Playbook

> - Design, harden, and audit platform-level security and governance for development where humans and AI coding agents work side by side. Use PROACTIVELY when the user wants to secure AI or coding agents, set up agent governance or guardrails, enforce least privilege for agents, build an audit trail of agent actions, run or modernize vulnerability management, achieve compliance for coding agents (SOX, GDPR, FedRAMP, ITAR, IL4-IL6, NIS2, DORA), evaluate a sovereign platform or cloud strategy, adopt policy-as-code or shift-down security, triage CVEs at scale, control agent network/egress access, or asks "can we trust agents in a regulated environment", "who approves what an agent ships", "what does the auditor need from our AI workflow". Fire on related phrasing, not just exact matches. For maturity scoring use asdlc-maturity-assessment; for platform architecture (including sovereign variants) use idp-adp-architect; for verifying a single agent's output, agent-trust-auditor.

## Facts
- Page: https://tashan.sh/capability/skill-cloud-byte-consulting-platform-security-playbook
- tashan id: skill:Cloud-Byte-Consulting/platform-security-playbook
- Source: https://github.com/Cloud-Byte-Consulting/plugins
- Type: skill
- Category: security
- tashan score: not scored (catalogued only — too little public evidence)
- Adoption: 9.0
- Upkeep: 95.0
- Freshness: 90.0
- Evidence coverage: 84% of the inputs this score can use
- Health: active
- Instruction depth: not yet graded
- License: Apache-2.0
- Official: no

## Install

```sh
cp -r platform-security-playbook ~/.claude/skills/
```

## Security audit
Not scanned. We audit npm-published capabilities; this one has no npm package we can resolve, or has not reached the queue. This is not a clean bill of health.

---
Measured 2026-08-22 by tashan (https://tashan.sh) from public evidence. Scorer s5.
