# Security

> - You MUST use this skill before approving or merging any code that touches auth, input handling, permissions, or external data. Use when the review focus is specifically on security vulnerabilities, attack surface, or compliance — not general code quality. Stronger signals: "security review", "check for vulnerabilities", "is this safe", "audit this", "OWASP", "injection", "auth check", "XSS", "SQL injection", "pentest", "threat model". Can run standalone or as a follow-up after sextant:review-code. Use sextant:review-code instead when the goal is general code quality without a security focus.

## Facts
- Page: https://tashan.sh/capability/skill-hellotern-security
- tashan id: skill:hellotern/security
- Source: https://github.com/hellotern/Sextant
- Type: skill
- Category: security
- tashan score: 31.0 / 100
- Adoption: 20.0
- Upkeep: 47.0
- Freshness: 62.0
- Evidence coverage: 84% of the inputs this score can use
- Health: active
- Instruction depth: not yet graded
- License: MIT
- Official: no

## Install

```sh
cp -r security ~/.claude/skills/
```

## Security audit
Not scanned. We audit npm-published capabilities; this one has no npm package we can resolve, or has not reached the queue. This is not a clean bill of health.

---
Measured 2026-08-14 by tashan (https://tashan.sh) from public evidence. Scorer s5.
