skills/council/forge/hw-security-signoff/SKILL.md
Use when a hardware design needs security sign-off before tape-out. Defines the builder-to-auditor handoff contract between Foundry (constructive design) and Forge (security review). Covers security review prerequisites, artifact checklist, sign-off criteria, and conditional approval workflow. Do not use for RTL security review itself (use rtl-security-review) or design flow guidance (use foundry/chip-design-flow).
npx skillsauth add dtsong/my-claude-setup hw-security-signoffInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Define the handoff contract between Foundry (builder) and Forge (security auditor) for hardware security sign-off. Ensure all security-critical design artifacts are delivered, reviewed, and approved before tape-out commitment.
Coordinates the handoff process between builder and auditor roles. Does not perform the security review itself (delegates to rtl-security-review, microarch-analysis, physical-design-security). Does not modify design files.
No user-provided values are used in commands or file paths. All inputs are treated as read-only analysis targets.
Foundry must deliver the following before security review begins:
Reject handoff if any artifact is missing. Document gaps and return to Foundry.
Dispatch to Forge specialist skills based on scope:
Track review progress per module and per skill.
Document decision with: reviewer, date, scope covered, open items (if conditional), and next review trigger.
Compaction resilience: If context was lost, re-read the Inputs section for the design under review, check the Progress Checklist, then resume from the earliest incomplete step.
| Field | Value | |-------|-------| | Design | ... | | Reviewer | Forge | | Date | ... | | Decision | Approved / Conditional / Blocked | | Scope | Modules A, B, C | | Open items | ... |
| ID | Module | Category | Severity | Status | Owner | |----|--------|----------|----------|--------|-------| | F1 | access_ctrl | Bypass | Critical | Fixed | Foundry | | F2 | debug_if | Leakage | High | Mitigated | Foundry |
development
Use when the council needs to surface organizational knowledge buried across multiple internal sources (wikis, design docs, ADRs, past tickets, postmortems, chat archives, code repos). Plans where to look, what to cross-reference, and how to synthesize findings into evidence the council can act on. Do not use for external market research (use competitive-analysis), library evaluation (use library-evaluation), or technology trend assessment (use technology-radar).
testing
Use to convert a Word .docx file to PDF and/or verify its page count. Triggers on: converting docx to pdf, rendering a document, checking how many pages a docx produces, or asserting a page-count constraint (e.g. a resume must stay 2 pages). Wraps LibreOffice headless conversion.
development
Security audit checklist for web applications. Use when reviewing, auditing, or hardening a web app's security posture. Covers rate limiting, auth headers, IP blocking, CORS, security middleware, input validation, file upload limits, ORM usage, and password hashing. Triggers on requests like "review security", "harden this app", "security audit", "check for vulnerabilities", or when building/reviewing API endpoints.
development
Interactive wizard to craft effective prompts using Claude Code best practices