Apply baseline engineering security guidance: secrets handling, secure defaults, threat modelling references, and review checkpoints for auth, data flow, pipelines, and external integrations. Use when a change has security impact but does not require a full standalone AppSec engagement.
$npx -y skills add managedcode/dotpilot --skill mcaf-security-baselineInstalls into the current project.
Run `npx skills use "https://github.com/managedcode/dotpilot" --skill "managedcode/dotpilot/mcaf-security-baseline"` and follow the generated skill instructions now. Read its complete output, redirecting it to a temporary file first if necessary. Resolve relative paths from the supporting-files directory it provides.
Use the skills in "https://github.com/managedcode/dotpilot" that are relevant to the current task. Run `npx skills add "https://github.com/managedcode/dotpilot"` and select the relevant skills, then follow their instructions.