Rewrite 548 skill descriptions to the activation rubric

Each rewritten description now states both what the skill does (concrete
capability, named tools/artifacts) and an explicit when-to-use trigger,
improving agent discovery/activation. Grounded in each skill's own body;
changes confined to the `description` field only (bodies and all other
frontmatter untouched). Produced by a gated audit->rewrite->recheck loop
(548 -> 0 flagged) with a sampled anti-invention check (0 ungrounded).

Schema: 817/817 pass. Framework-ID gate: 0 defects.
This commit is contained in:
Mahipal
2026-08-02 09:32:13 -07:00
parent 04a207702e
commit 2fb6a9faff
548 changed files with 2189 additions and 1915 deletions
@@ -1,14 +1,11 @@
---
name: implementing-api-key-security-controls
description: 'Implements secure API key generation, storage, rotation, and revocation
controls to protect API authentication credentials from leakage, brute force, and
abuse. The engineer designs API key formats with sufficient entropy, implements
secure hashing for storage, enforces per-key scoping and rate limiting, monitors
for leaked keys in public repositories, and builds key rotation workflows. Activates
for requests involving API key management, API key security, key rotation policy,
or API credential protection.
'
description: 'Implements secure API key generation with sufficient entropy, server-side
hashing (SHA-256/bcrypt) instead of plaintext storage, per-key scoping to endpoints/IPs/rate
limits, zero-downtime rotation, and automated leak monitoring across GitHub repos,
logs, and client-side code. Use when designing API key formats, building key rotation
or revocation workflows, or protecting server-to-server API credentials from leakage,
brute force, and abuse.'
domain: cybersecurity
subdomain: api-security
tags: