What problem does it solve? Teams often treat security as a final gate or a separate team's job, causing late-stage vulnerabilities, slow releases, and blame-driven culture. This Skill provides a principles-first mindset framework for embedding security continuously into planning, coding, CI/CD, and operations. ## Core Features & Use Cases - Mindset Shift Framework: Maps old security attitudes (gatekeeper, checkbox compliance) to DevSecOps thinking (shared responsibility, continuous feedback loops). - Phase-by-Phase Behavior Patterns: Concrete security questions to ask during planning, coding, CI/CD, and operations. - Anti-Pattern Detection: Identifies common failures like tool-first approaches, alert fatigue, and security theater. - Curated Reference Library: Frameworks (NIST SSDF, OWASP SAMM, SLSA), tool categories (SAST, DAST, SCA, IaC), certifications, and books. - Use Case: A tech lead designing a new CI/CD pipeline uses this Skill to frame security decisions, select measurable metrics like MTTR and coverage, and avoid gatekeeper bottlenecks before choosing specific scanning tools. ## Quick Start Ask the agent to review your team's development workflow and suggest how to apply DevSecOps principles to integrate security earlier in the lifecycle.