Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/d4rkninja/arcforge/security-privacynpx skills add d4rkNinja/arcforge --skill security-privacygit clone --depth 1 https://github.com/d4rkNinja/arcforgeWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/d4rkninja/arcforge/security-privacy)<a href="https://agentmods.dev/skills/d4rkninja/arcforge/security-privacy"><img src="https://agentmods.dev/badge/skills/d4rkninja/arcforge/security-privacy.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00081 | $0.02421 |
| Opus 5 | $0.00041 | $0.01210 |
| Sonnet 5 | $0.00016 | $0.00484 |
| Haiku 4.5 | $0.00008 | $0.00242 |
Grade A, and why
security-privacy scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 149 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Think Through Security & Privacy
Overview
Production guidance for protective controls. Each reference paper captures the failures that audits find late: secrets in config and logs, home-grown crypto, disabled certificate verification, PII without retention or deletion paths, and abuse protections that rate-limit the wrong dimension.
Core principle: Controls attach to data and actions, not to layers. Every secret, sensitive field, and privileged action has a lifecycle — generation, use, rotation, redaction, deletion — that must be enforced somewhere concrete.
Domain Law
NO SECURITY OR PRIVACY CHANGE WITHOUT:
1. the minimum required primary paper(s) for the control selected from the context table;
2. the asset, actor, and trust boundary named before choosing a control;
3. "Existing-codebase checks" run when changing existing protections;
4. every applicable MUST/NEVER mapped to an enforcement point, a test,
or a documented risk-accepted exception.
When to Use
Use this skill when thinking through, reviewing, changing, or verifying:
- secrets: storage, injection, rotation, scoping, and audit;
- encryption at rest/in transit and key management;
- TLS configuration, certificate rotation, and PKI assumptions;
- crypto primitive selection: hashing, MACs, ciphers, nonce management;
- password and token hashing parameters;
- sensitive-data classification, minimization, retention, and deletion propagation;
- log/trace/error redaction and export controls;
- abuse protection: brute force, credential stuffing, enumeration, scraping, fraud;
- feature flag safety and kill switches;
- temporary and expiring data (sessions, tokens, uploads, exports);
- randomness and token generation (IDs, secrets, nonces).
When Not to Use
- Login/session/OAuth/permission flows: use
auth-access. - API-surface attack classes (injection, object-level authorization, mass assignment): use
api-contracts(062 pairs here). - Rate-limit mechanics: use
resilience-flow-control(038). - Whole-system threat models and zero-trust architecture: use
system-architecture-harness. - Untrusted code execution sandboxes for AI: use
ai-agent-system-architecture.
What ships with it
12 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- agents/openai.yaml 289 B
- examples/worked-example-secrets-and-redaction.md 4.2 KB
- references/papers/061-security-fundamentals.md 32 KB
- references/papers/062-web-api-security.md 31 KB
- references/papers/063-secrets-management.md 41 KB
- references/papers/064-cryptography.md 40 KB
- references/papers/065-tls-pki.md 38 KB
- references/papers/066-privacy-and-sensitive-data.md 44 KB
- references/papers/067-abuse-protection.md 37 KB
- references/papers/068-feature-flags.md 35 KB
- references/papers/126-temporary-data.md 36 KB
- references/papers/127-randomness-and-token-generation.md 39 KB
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday Changed · +4 lines 7c2e17635df9
- 5d ago First seen · 145 lines · 81 tokens per session scan A f2f3490134be
security-privacy is a skill published in the GitHub repository d4rkNinja/arcforge (16 stars, last pushed yesterday), licensed MIT. It adds 81 tokens to every session and 2,421 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
sparc-methodology
SPARC (Specification, Pseudocode, Architecture, Refinement, Completion) comprehensive development methodology with multi-agent orchestration.
code-to-diagram
Analyze codebases and automatically generate architecture diagrams, flowcharts, and org charts. Uses AST parsing to map import dependencies for Python, JS/TS, Go, and Java, outputting Mermaid or SVG files. Triggered when users ask to visualize code architecture, understand dependencies, draw a flowchart, or create a…
architecture-diagram
Dark-themed SVG architecture/cloud/infra diagrams as HTML.
studio
Architecture Studio control plane — initialize or inspect a studio workspace, create and register projects, or route an architecture/AEC task to the right agent or skill. Use when the user runs /as:studio, asks to set up or open their studio, manage its projects, or describes a task without naming a skill.
csv-to-sif
Export a project's FF&E product-library CSV as dealer-system SIF. Use to produce a .sif schedule; use sif-to-csv for the reverse direction.
modular-skills
Build composable skill modules with hub-and-spoke loading. Use when token budget is tight.