-
AI Skill
- Access Fingerprinter
- Accessibility Design
- Accountability Profile Builder
- Accountability Profile Verification
- Ad Campaign Optimization
- Advisor Action Framework
- AEO RECOMMENDATION TOOL - SYSTEM PROMPT
- Agentic Task Execution
- AI Candor Probe
- AI Citation Tracking
- AI Content Authenticity Detection
- AI Coworker Trust Protocol
- Ai Document Analysis
- AI Inference Boundary Review
- AI Journalism
- AI Project Showcase Skill
- AI Self-Report Calibration
- AI Vision Diagnosis
- Antigravity Browser QA
- Antigravity Parallel Debug
- Antigravity Test Orchestration
- Apache HTTPD Configuration
- API Design
- Appellate Brief Writer
- Apple Human Interface Design System
- AppSec Engineer — API Security Specialist
- AppSec Engineer — Cloud & Container Security Specialist
- AppSec Engineer — DevSecOps Specialist
- AppSec Engineer — IAM Security Specialist
- AppSec Engineer — Security Testing & Incident Response Specialist
- Arborist / Tree Care Specialist
- Atlanta Gardening
- Atlanta Guide
- B2B Media Consulting
- Botanical Garden Taxonomist
- Botanist / Plant Scientist
- Brand Voice Development
- Breach Data Analysis Specialist
- Business Proposal Evaluation
- Canvas Strategic Nonviolence
- Career Assessment
- Celery Task Management
- Chapter 22: Safety & Guardrails
- Chapter 26: Security Standards
- Chapter 28: Cursor Skills
- Children's Garden Educator
- Citation Checker
- Civic Tech Privacy Architecture
- Civil Resistance Theory
- Claims Integrity Audit
- CloudKit + Tauri Debugging
- Code Review
- Community Engagement Features
- Community Engagement Manager
- Competitive Analysis
- Conflict Zone Osint Specialist
- Conservation Biologist
- Content Gap Analysis
- Content Strategy
- Contract Analysis
- Conversational UI Design
- Cooking Technique Tutorial
- Copywriting
- Corporate Intelligence Investigator
- Culinary Knowledge Lookup
- Curator of Living Collections
- Customer Journey Methodology
- Customer Support
- Cyber Threat Literacy Journalist
- Dark Web Literacy Journalist
- Data Interpretation
- Democratic Health Monitoring
- Democratic Health Monitoring
- Dependency Hygiene
- Design Systems
- Dify Knowledge Base Management
- Director of Education
- Director of Horticulture
- Director of Science & Research
- Dive Conditions Forecasting
- Dive Planning
- Dive Site Data Ingestion
- Diversity, Equity & Inclusion (DEI) Coordinator
- Docker Compose Management
- Document Research Specialist
- Domain Infrastructure Investigator
- Education Curator
- Education Program Coordinator
- Eighth Amendment Legal Expert
- Election Law and Administration
- Election Threat Scenario Planner
- Election Threat Scoring
- Email Campaign Automation
- Email Parsing — Travel Bookings
- Environmental Osint Specialist
- Estate Accounting
- Estate and Trust Management
- Estate Document Extraction
- Estate Jurisdiction Engine
- Estate Manager — Build Plan
- Estate Manager — Updated Product Roadmap
- Estate Professional — CPA / Accountant
- Estate Professional — Elder Law Attorney
- Estate Professional — Enrolled Agent
- Estate Professional — Estate Planning Attorney
- Estate Professional — Financial Advisor
- Estate Professional — Insurance Agent
- Estate Professional — Probate Attorney
- Estate Professional — Probate Litigation Attorney
- Estate Professional — Real Estate Agent
- Estate Professional — Real Estate Appraiser
- Estate Professional — Real Estate Attorney
- Estate Professional — Tax Attorney
- Estate Professional — Title Company
- Estate Task Automation
- EventKit Calendar Sync
- Executive Advisor Board — Build Plan
- Executive Advisor Board — Updated Product Roadmap
- Executive Board Advisor
- Executive CCO (Chief Customer Success Officer)
- Executive CEO
- Executive CFO
- Executive CHRO
- Executive CMO
- Executive COO
- Executive CPO (Chief Product Officer)
- Executive CRO (Chief Revenue Officer)
- Executive CTO
- Executive General Counsel
- Expat Planning
- Expat Tax Compliance
- Fact-Checking
- Family Gamification Design
- FastAPI Development
- Federal Register API Integration
- FIFA 2026 World Cup Travel Advisory
- Fifth Amendment Legal Expert
- Financial Analysis
- First Amendment Legal Expert
- Flask Application Development
- FLUX Image Generation
- FLUX Operations
- Fourteenth Amendment Legal Expert
- Fourth Amendment Legal Expert
- Garden Technician
- Gardener / Groundskeeper
- Gene Sharp 198 Methods
- Generative Engine Optimization
- Geolocation Verification Specialist
- GIS / Mapping Specialist
- Grateful Dead Historian
- Greenhouse Manager
- Greenhouse Technician
- Guided Content Journeys
- Head Gardener / Garden Manager
- Herbarium Curator
- Horticulturist
- Image Generation Service Operations
- Immigration Detention Rights Expert
- Immigration Know Your Rights Expert
- Immigration Removal Defense Expert
- Immigration Workplace Enforcement Expert
- Influencer Marketing
- Infrastructure Operations
- Infrastructure Upgrades
- Integrated Pest Management (IPM) Specialist
- Interaction Design
- Internship Program Coordinator
- Interview Coaching Design
- Investigation Workflow Designer
- Irrigation Specialist
- ITI Audience Development
- ITI Consulting Intake
- ITI Content Strategy
- ITI Financial Modeling
- ITI Marketing Tone & Brand Voice
- ITI MD to Wordpress HTML Converter
- ITI Quality Assurance
- ITI Report Synthesis
- ITI Strategic Planning
- ITI Technology Strategy
- ITI Token Compression Skill
- Java Development
- Journey Mapping
- Landing Page Optimization
- Lead Qualification
- Legal Research Specialist
- Litigation Support Ediscovery Analyst
- Local SEO Optimization
- Marine Life Identification
- Market Research
- MCP Client for Tauri
- MCP Server Development
- Meal Planning
- Media Verification Specialist
- Meeting Management
- Mental Load Equity Design
- Multi-Agent Deliberation Design
- Multilingual Content Management
- Music Discovery
- n8n + Dify Testing
- n8n Debugging
- n8n Workflow Development
- Network Analysis Specialist
- News Credibility Scoring
- Nginx Reverse Proxy
- Objection Handling
- Onboarding Design
- Osint Automation Frameworks
- Osint Identity Researcher
- Osint Training Curriculum Designer
- Patriot Access Fingerprinter
- Patriot News Orchestrator
- Patriot Press Freedom Tracker
- Patriot Private Citizen Inclusion Gate
- Patriot Sanity Check
- Patriot Source Scanner
- Patriot Speech Analyzer
- Patriot Voting Research
- Pinecone Embedding Management
- Podcast Production
- Policy Analyst Legislative Specialist
- Political Speech Analyzer
- Portfolio HTML Files - Creation Summary
- PostgreSQL Administration
- Presentation Design
- Press Release Writing
- PRISM ZIP Code → Zone Lookup
- Privacy Compliance
- Product Design
- Product Roadmap Update Prompt
- Professional Selection
- Project Management
- Prompt Auditor
- Proposal Evaluation
- Public Corruption Ombudsman
- Public Records Research Specialist
- Public Relations Manager
- RabbitMQ Messaging
- Recipe Formatting
- Redis Operations
- Release Management
- Requirements Writing
- Research Associate / Lab Technician
- Retirement Calculator Engine
- Roadmap Build Planning
- Safety Guardrails
- Salary Negotiation Frameworks
- Schema Markup Generation
- School Programs Specialist
- Scope Control
- Scouting Trip Planning
- Screenshot Capture Guide
- Secure Source Communication
- Seed Bank Curator
- SEO & AEO Optimization
- Separation of Powers Legal Expert
- Session Context Protocol
- Sixth Amendment Legal Expert
- Skills Index
- Social Media Content Calendar
- Spokesperson Profile Builder
- Stable Diffusion Image Generation
- Tauri Desktop Development
- Tavily & Pinecone Integrations
- Tavily API Quick Reference - Factchecker Plugin
- Tech Debt Analysis
- Technical Writing
- Tenth Amendment Legal Expert
- Test Plan Writing
- Therapeutic Horticulture Program Manager
- Transportation Osint Investigator
- Travel Planning
- Trump Corruption Accountability Tracker
- Trump Family Financial Tracker
- Trump Voter Impact Framing
- Truth Bridging Talking Points
- Truth Reconciliation Design
- Truth Reconciliation Implementation
- TSP Route Optimization
- Twenty Second Amendment Legal Expert
- UI Design
- Us Truth Reconciliation Roadmap
- UX Research
- Vibe Coding Guardrails
- Video Scripting
- Visual Brand Design
- Volunteer Coordinator
- Voter Suppression Law
- Voting Rights Act Expert
- Weather Underground PWS Integration
- Weather-Disease Modeling
- Wildlife Habitat Certification Guide
- Wireless Spectrum Osint Specialist
- WordPress Development
- WordPress Role-Based Access
- WordPress SEO Plugin Integration
- Workflow Adapter Integration
- Show Remaining Articles (283) Collapse Articles
-
Product Showcase
- AEO Optimizer Product Showcase
- AI News Cafe Product Showcase
- AI Project Showcase: Journey Mapper (Customer Journey Mapper)
- AI Project Showcase: SEO Assistant with LLM
- Estate Manager Product Showcase
- Executive Advisor Board Product Showcase
- Expat Advisor Showcase
- Factchecker Product Showcase
- Farmers Bounty Product Showcase
- Gardener's Bounty AI Assistant Product Showcase
- GD Claude Chatbot Product Showcase
- IT Influentials Agent POC Product Showcase
- IT Influentials Agent Product Showcase
- IT Influentials Express Agents Product Showcase
- My TravelPlanner Product Showcase
- Patriot Agent Product Showcase
- Patriot University Showcase
- ScubaGPT — Product Showcase
- ScubaGPT Showcase
- WordPress Plugin Clone Safety Checker Showcase
- Show Remaining Articles (5) Collapse Articles
-
ITI Knowledge System
- Chapter 1: Introduction
- Chapter 10: n8n — Debugging & Operations
- Chapter 11: Dify — Knowledge Bases & RAG
- Chapter 12: The ITI Workflow Adapter
- Chapter 13: The ITI Shared Library
- Chapter 14: WordPress Plugin Development
- Chapter 15: Desktop Apps with Tauri 2
- Chapter 16: Python Services
- Chapter 17: iOS & macOS with Swift
- Chapter 18: Claude & the Anthropic API
- Chapter 19: Prompt Engineering
- Chapter 2: Workspace Overview
- Chapter 20: Agents, Skills & Pipelines
- Chapter 21: Knowledge Bases
- Chapter 22: Safety & Guardrails
- Chapter 23: Build Session Protocol
- Chapter 24: Required Product Artifacts
- Chapter 25: Testing
- Chapter 26: Security Standards
- Chapter 27: Deployment
- Chapter 28: Cursor Skills
- Chapter 29: Cursor Rules
- Chapter 3: The Docker Stack
- Chapter 30: MCP Integrations
- Chapter 31: Builder and Agent Roles
- Chapter 32: Builder's Portfolio
- Chapter 33: Claims Integrity & Content Governance
- Chapter 4: Daily Operations
- Chapter 5: Infrastructure Upgrades
- Chapter 6: PostgreSQL & pgvector
- Chapter 7: Redis
- Chapter 8: Nginx Reverse Proxy
- Chapter 9: n8n — Workflow Development
- Show Remaining Articles (18) Collapse Articles
-
AI Agent
-
User Guide
- ADMIN-SHORTCODES.html Update Summary
- Factchecker Plugin - Installation Guide
- Factchecker Plugin - Troubleshooting Guide
- Farmers Bounty - Quick Start Guide
- Farmers Bounty - Troubleshooting Guide
- Farmers Bounty - User Guide
- Farmers Bounty Chatbot - Complete Documentation
- Farmers Bounty Desktop User Guide
- Farmers Bounty Plugin - Gardener's Review Guide
- Farmers Bounty Plugin v6.6.0 - Release Notes
- Farmers Bounty v2.0 - Complete User Guide
- Farmers Bounty v5.3.0 - Complete User Guide
- SEO Assistant with LLM
- 🌱 Farmers Bounty Homepage Shortcode - Quick Start
- 🌱 Farmers Bounty Shortcodes
- 🌹 Grateful Dead Chatbot - Quickstart Guide ⚡
- Show Remaining Articles (1) Collapse Articles
-
Requirements
-
ScubaGPT
-
Grateful Dead Chatbot
-
Farmers Bounty
- 01 current state analysis
- 02 architecture overview
- 03 data sources
- 05 cost analysis
- 06 database schema
- 08 ui ux changes
- 09 ai context optimization
- 10 testing validation
- 11 risk mitigation
- 12 implementation checklist
- ADMIN-SHORTCODES.html Update Summary
- Atlanta Gardening
- Beneficial Insects Guide for Georgia Gardens
- Botanical Garden Taxonomist
- Children's Garden Educator
- Farmers Bounty - Quick Start Guide
- Farmers Bounty - Troubleshooting Guide
- Farmers Bounty - User Guide
- Farmers Bounty Chatbot - Complete Documentation
- Farmers Bounty Desktop User Guide
- Farmers Bounty Plugin - Gardener's Review Guide
- Farmers Bounty Plugin v6.6.0 - Release Notes
- Farmers Bounty v2.0 - Complete User Guide
- Farmers Bounty v5.3.0 - Complete User Guide
- Glossary
- Integrated Pest Management (IPM) Specialist
- PRISM ZIP Code → Zone Lookup
- Public Relations Manager
- Recipe Formatting
- Research Associate / Lab Technician
- School Programs Specialist
- Seed Bank Curator
- Volunteer Coordinator
- Weather-Disease Modeling
- Wildlife Habitat Certification Guide
- 🌱 Farmers Bounty Homepage Shortcode - Quick Start
- 🌱 Farmers Bounty Shortcodes
- Show Remaining Articles (22) Collapse Articles
-
Technical Document
- Accessibility Design
- Agentic Task Execution
- AI Candor Probe
- AI Coworker Trust Protocol
- AI Inference Boundary Review
- AI Vision Diagnosis
- Antigravity Browser QA
- Antigravity Parallel Debug
- Antigravity Test Orchestration
- AppSec Engineer — IAM Security Specialist
- Chapter 22: Safety & Guardrails
- Chapter 26: Security Standards
- Civic Tech Privacy Architecture
- ClaimReview Schema Integration
- Claims Evidence Registry
- Code Review
- IT Influentials Express Agents Product Showcase
- Java Development
- MCP Client for Tauri
- MCP Server Development
- Nginx Reverse Proxy
- Pinecone Embedding Management
- PostgreSQL Administration
- Product Roadmap Update Prompt
- Prompt Auditor
- RabbitMQ Messaging
- Redis Operations
- Release Management
- Retirement Calculator Engine
- Roadmap Build Planning
- Schema Markup Generation
- ScubaGPT — Architecture
- ScubaGPT Safety Guardrails - Quick Reference
- Session Context Protocol
- Stable Diffusion Image Generation
- Tauri Desktop Development
- Tavily & Pinecone Integrations
- Tavily API Quick Reference - Factchecker Plugin
- Tech Debt Analysis
- Test Plan Writing
- Travel Planner — n8n + Dify Integration Guide
- UI Design
- UX Research
- Vibe Coding Guardrails
- WordPress Plugin Clone Safety Checker Showcase
- Workflow Adapter Integration
- Show Remaining Articles (31) Collapse Articles
-
Answer Engine Optimizer
-
SEO Optimizer
-
Travel Planner
-
Fact Checker
-
Estate Manager
-
ITI Operations
- Access Fingerprinter
- Accessibility Design
- Advisor Action Framework
- Agentic Task Execution
- AI Candor Probe
- AI Content Authenticity Detection
- AI Coworker Trust Protocol
- AI Inference Boundary Review
- AI Project Showcase Skill
- AI Self-Report Calibration
- Antigravity Browser QA
- Antigravity Parallel Debug
- Antigravity Test Orchestration
- Apple Human Interface Design System
- AppSec Engineer — API Security Specialist
- AppSec Engineer — DevSecOps Specialist
- Chapter 32: Builder's Portfolio
- CloudKit + Tauri Debugging
- Code Review
- Content Strategy
- Customer Journey Methodology
- Customer Support
- Data Interpretation
- Dependency Hygiene
- End-User Documentation Requirements Document
- Farmers Bounty Plugin - Gardener's Review Guide
- Generative Engine Optimization
- Guided Content Journeys
- Influencer Marketing
- Infrastructure Upgrades
- Interaction Design
- IT Influentials Agent POC Product Showcase
- IT Influentials Agent Product Showcase
- IT Influentials Express Agents Product Showcase
- ITI Audience Development
- ITI Consulting Intake
- ITI Financial Modeling
- ITI Quality Assurance
- ITI Report Synthesis
- ITI Strategic Planning
- ITI Token Compression Skill
- Market Research
- MCP Server Development
- Multi-Agent Deliberation Design
- Multilingual Content Management
- n8n Debugging
- n8n Workflow Development
- Pinecone Embedding Management
- Privacy Compliance
- Product Roadmap Update Prompt
- Project Management
- Prompt Auditor
- Proposal Evaluation
- Redis Operations
- Release Management
- Requirements Writing
- Roadmap Build Planning
- Safety Guardrails
- Scope Control
- Screenshot Capture Guide
- Stable Diffusion Image Generation
- Tavily & Pinecone Integrations
- Technical Writing
- Test Plan Writing
- UI Design
- UX Research
- Vibe Coding Guardrails
- Wordpress Plugin Install Safety Features
- Show Remaining Articles (53) Collapse Articles
-
ITI Marketing
- Articles coming soon
-
Patriot University
-
Personal Assistant
Chapter 26: Security Standards
Chapter 26: Security Standards
Last Updated: 2026-03
## 26.1 Non-Negotiable Rules
These rules apply to all ITI code on all platforms. No exceptions. AI-generated code that violates these rules must be fixed before it is committed.
| Rule | Applies To |
|——|———–|
| Never hardcode API keys, passwords, or secrets | All platforms |
| Sanitize all user input before processing or storing | All platforms |
| Escape all output before rendering to the user | All platforms |
| Never commit .env, credential files, or API keys to Git | All platforms |
| Never use eval(), exec(), or equivalent on user-controlled data | PHP, JS, Python |
| Log all security events (failed auth, invalid tokens, unauthorized access) | All platforms |
| Use prepared statements or parameterized queries for all database operations | PHP, Python, Rust |
| Validate all input server-side, even when validated client-side | All web platforms |
26.2 Secret Management by Platform
PHP (WordPress)
// Store: always encrypt API keys before saving to wp_options
update_option('iti_my_plugin_api_key', iti_encrypt($api_key));
// Retrieve: decrypt on use
$api_key = iti_decrypt(get_option('iti_my_plugin_api_key', ''));
Never use define() for API keys. Never put keys in wp-config.php.
Python (Flask / FastAPI)
# .env file (never committed)
ANTHROPIC_API_KEY=sk-ant-...
TAVILY_API_KEY=tvly-...
# In code
import os
from dotenv import load_dotenv
load_dotenv()
api_key = os.environ['ANTHROPIC_API_KEY'] # raises KeyError if missing — intentional
TypeScript (Node.js / Tauri frontend)
// .env file (never committed)
VITE_SOME_PUBLIC_KEY=... // Only non-secret values
// For secrets in Tauri: use IPC to read from Keychain, never store in frontend code
const apiKey = await invoke<string>('get_api_key', { service: 'anthropic' });
Swift (iOS/macOS)
// Store in Keychain
try KeychainService.store(key: "ANTHROPIC_API_KEY", value: apiKey)
// Retrieve from Keychain
let apiKey = try KeychainService.retrieve(key: "ANTHROPIC_API_KEY")
Rust (Tauri backend)
// Read from environment (set via tauri.conf.json or OS env)
let api_key = std::env::var("ANTHROPIC_API_KEY")
.map_err(|_| "ANTHROPIC_API_KEY not set".to_string())?;
26.3 Input Sanitization by Platform
PHP (WordPress)
// Text: strip HTML and extra whitespace
$clean = sanitize_text_field($_POST['field'] ?? '');
// Email: validate and sanitize
$email = sanitize_email($_POST['email'] ?? '');
if (!is_email($email)) {
wp_send_json_error(['message' => 'Invalid email.']);
}
// URL: validate and sanitize
$url = esc_url_raw($_POST['url'] ?? '');
// Integer: ensure positive integer
$count = absint($_POST['count'] ?? 0);
// HTML content: strip disallowed tags and attributes
$html = wp_kses_post($_POST['content'] ?? '');
Warning:
sanitize_text_field()is for plain text. Never use it on HTML content — usewp_kses_post()instead.
Python
from pydantic import BaseModel, Field, validator
class UserRequest(BaseModel):
message: str = Field(..., min_length=1, max_length=10000)
email: str | None = None
@validator('email')
def validate_email(cls, v):
if v is not None:
import re
if not re.match(r'^[^@]+@[^@]+\.[^@]+$', v):
raise ValueError('Invalid email format')
return v
TypeScript
function sanitizeInput(input: unknown): string {
if (typeof input !== 'string') {
throw new Error('Expected string input');
}
return input.trim().slice(0, 10000); // enforce max length
}
26.4 Output Escaping by Platform
PHP (WordPress)
// HTML context: escape for display in HTML
echo esc_html($user_data);
// HTML attribute context
echo '<input value="' . esc_attr($value) . '">';
// URL context
echo '<a href="' . esc_url($url) . '">';
// JavaScript context
echo '<script>var data = ' . wp_json_encode($data) . ';</script>';
Python (Jinja2 templates)
Jinja2 auto-escapes by default when autoescape=True. Verify this is set:
from jinja2 import Environment, select_autoescape
env = Environment(autoescape=select_autoescape(['html', 'xml']))
React/TypeScript
React escapes by default when rendering with {}. Never use dangerouslySetInnerHTML unless the content has been explicitly sanitized with a library like DOMPurify.
26.5 CSRF Protection (WordPress)
Every WordPress AJAX handler must verify a nonce:
// On the frontend, output a nonce for the AJAX action
wp_nonce_field('iti_my_action_nonce', 'nonce');
// Or in JavaScript
const nonce = iti_my_plugin_data.nonce; // passed via wp_localize_script
// On the backend, verify the nonce
check_ajax_referer('iti_my_action_nonce', 'nonce');
// This function wp_die()'s if the nonce is invalid — no further code needed after it
26.6 Database Security
WordPress (wpdb)
// Always use prepare() for parameterized queries
global $wpdb;
$result = $wpdb->get_results(
$wpdb->prepare(
"SELECT * FROM {$wpdb->prefix}my_table WHERE user_id = %d AND status = %s",
$user_id,
$status
)
);
Warning: Never concatenate user input directly into SQL strings.
"SELECT * FROM table WHERE id = " . $_POST['id']is a SQL injection vulnerability.
Python (psycopg2 / SQLAlchemy)
# psycopg2 — use parameterized queries
cursor.execute("SELECT * FROM sessions WHERE user_id = %s", (user_id,))
# SQLAlchemy ORM — parameterized by default
result = session.query(Session).filter(Session.user_id == user_id).all()
Rust (rusqlite)
// Use named parameters
conn.query_row(
"SELECT * FROM sessions WHERE user_id = ?1",
params![user_id],
|row| row.get(0),
)?;
26.7 Git Security
# Ensure .env is in .gitignore
echo ".env" >> .gitignore
echo "*.env" >> .gitignore
# Before committing, verify no secrets are staged
git diff --staged | grep -i "api_key\|password\|secret\|token"
Warning: If a secret is accidentally committed, it is in Git history even after deletion. Immediately rotate the compromised key and purge the history.
26.8 Security Event Logging
Log these events with sufficient context to enable audit and incident response:
| Event | What to Log |
|---|---|
| Failed authentication | Timestamp, user/IP, reason |
| Invalid nonce | Timestamp, action, user/IP |
| Unauthorized access attempt | Timestamp, user, resource, action |
| API key error | Timestamp, service, error code (not the key itself) |
| Unusual data access | Timestamp, user, what was accessed |
// WordPress logging example
error_log(sprintf(
'[ITI Security] Unauthorized access attempt: user=%d, action=%s, ip=%s, time=%s',
get_current_user_id(),
sanitize_text_field($_POST['action'] ?? 'unknown'),
$_SERVER['REMOTE_ADDR'] ?? 'unknown',
current_time('mysql')
));
26.9 Application Security Skills
For deeper security analysis beyond coding standards, five application security skills are available:
| Skill | Specialty |
|---|---|
appsec-api-security-engineer |
API attack surface analysis, rate limiting, abuse prevention |
appsec-cloud-container-security-engineer |
Kubernetes hardening, image scanning, IaC review |
appsec-devsecops-engineer |
CI/CD pipeline security, SAST/DAST, supply chain hardening |
appsec-iam-security-engineer |
OAuth/OIDC hardening, JWT analysis, authorization models |
appsec-security-testing-ir-engineer |
Pen testing, fuzzing, incident response, forensics |
All five share a common core of threat modeling (STRIDE/PASTA), secure code review, and vulnerability assessment with CVSS scoring.
Previous: Chapter 25 — Testing | Next: Chapter 27 — Deployment
