Architecture decision · Accepted
ADR-0002: The security reviewer is published as an open-source skills pack
Context. The security reviewer role found a real hole in its first week (see ADR 1 and the first field note). Its prompt was written for one company: it named Blankitt’s auth model, tenant model, secret names and deploy commands. The most widely used open skills pack for coding agents, Matt Pocock’s, has no security step at all, and its scope document closes new-skill contributions. A role that only works inside one repository cannot be compared, criticised or improved by anyone else.
Decision. The role is split in two. The reusable part becomes five skills in a public repository, MIT licensed, in the same file shape as the Pocock pack so the same installers work: threat model a service, review changes against that model, audit secrets, gate a release, and a setup skill that records how a given repository ships. The company-specific part (auth model, tenant model, deploy command, secret store) moves into two files the skills read from the target repository, written by the setup and threat-model skills. One rule binds every skill: it reads and reports, and the only files it writes are its own reports. A second bucket for people who run systems rather than write them is listed and empty until each skill has been tested on a real system.
Consequences. The role card in this journal and the public pack are now the same thing, so a change to one is visible in the other. Blankitt’s own reviews run from the public skills plus the two local files, which is a test the pack passes every week or it does not. The pack’s install count becomes a number the Monday page can report. The cost is maintenance of a public repository with a scope rule and an issue bar, and the discipline of never letting a company fact leak back into a skill.