Data Security Review
data-security
Assess data security controls: classification, access, encryption, retention, and exposure risk.
SKILL.md
Full skill instructions
Data Security Review
Purpose
Evaluate confidentiality and integrity controls for data across storage, transit, and access paths.
Trigger
- Handling sensitive data in new/changed features.
- Security assessments and release gates.
Procedure
- Classify data types and sensitivity levels.
- Verify at-rest and in-transit encryption controls.
- Evaluate authentication/authorization boundaries.
- Check retention, deletion, and auditability requirements.
- Report exposure risks and remediation priorities.
Output Contract
- Data security findings with severity and remediation plan.
Governance Notes
- High/critical findings are merge-blocking unless risk-accepted.
References
agents/security-reviewer.mdskills/review/security/SKILL.md
