Claude
Skills
Sign in
Back

eng-team

Included with Lifetime
$97 forever

Secure engineering team skill providing methodology guidance for building security-hardened software. Invoked when users request system design, implementation, code review, testing, CI/CD security, or incident response with security considerations. Routes to 10 specialized agents covering architecture through post-deployment. Integrates NIST SSDF governance, Microsoft SDL phases, OWASP ASVS verification, SLSA supply chain integrity, and DevSecOps automation patterns.

Design

What this skill does


# Eng-Team Skill

> **Version:** 1.0.0
> **Framework:** Jerry Eng-Team
> **Constitutional Compliance:** Jerry Constitution v1.0
> **SSOT References:** ADR-PROJ010-001 (Agent Team Architecture), ADR-PROJ010-002 (Skill Routing & Invocation), ADR-PROJ010-003 (LLM Portability)
> **Project:** PROJ-010 Cyber Ops | EPIC-003 (/eng-team Skill Build) | FEAT-020 through FEAT-025

## Document Sections

| Section | Purpose |
|---------|---------|
| [Document Audience](#document-audience-triple-lens) | Triple-Lens audience guide |
| [Purpose](#purpose) | Skill overview and key capabilities |
| [When to Use This Skill](#when-to-use-this-skill) | Activation triggers |
| [Available Agents](#available-agents) | 10-agent roster with roles and output locations |
| [Invoking an Agent](#invoking-an-agent) | Three invocation methods with examples |
| [Orchestration Flow](#orchestration-flow) | 8-step sequential phase-gate workflow |
| [State Passing Between Agents](#state-passing-between-agents) | Output keys and handoff data |
| [Mandatory Persistence](#mandatory-persistence-p-002) | P-002 file persistence requirements |
| [Layered SDLC Governance](#layered-sdlc-governance) | 5-layer governance model (AD-008) |
| [Adversarial Quality Mode](#adversarial-quality-mode) | /adversary integration and criticality escalation |
| [Constitutional Compliance](#constitutional-compliance) | Governing principles |
| [Quick Reference](#quick-reference) | Common workflows and agent selection hints |
| [Agent Details](#agent-details) | Agent file paths |
| [Routing Disambiguation](#routing-disambiguation) | When this skill is the wrong choice |
| [References and Traceability](#references-and-traceability) | ADR baseline, architecture decisions, research provenance |

## Document Audience (Triple-Lens)

This SKILL.md serves multiple audiences:

| Level | Audience | Sections to Focus On |
|-------|----------|---------------------|
| **L0 (ELI5)** | New users, stakeholders | [Purpose](#purpose), [When to Use This Skill](#when-to-use-this-skill), [Quick Reference](#quick-reference) |
| **L1 (Engineer)** | Developers invoking agents | [Invoking an Agent](#invoking-an-agent), [Agent Details](#agent-details), [Adversarial Quality Mode](#adversarial-quality-mode) |
| **L2 (Architect)** | Workflow designers | [Orchestration Flow](#orchestration-flow), [State Passing Between Agents](#state-passing-between-agents), [Layered SDLC Governance](#layered-sdlc-governance) |

---

## Purpose

The Eng-Team skill provides a structured secure software engineering framework through 10 specialized agents. Each agent produces **persistent artifacts** that survive context compaction, enforce security standards at every phase, and build a cumulative knowledge base of security-hardened engineering decisions.

### Key Capabilities

- **Secure Architecture** -- System design with threat modeling (STRIDE/DREAD/PASTA) and architecture decision records
- **Implementation Planning** -- Standards enforcement, dependency governance, and SAMM maturity assessment
- **Secure Backend Engineering** -- Server-side implementation with OWASP Top 10 and ASVS verification
- **Secure Frontend Engineering** -- Client-side implementation with XSS prevention, CSP, and CORS hardening
- **Secure Infrastructure** -- IaC security, container hardening, SBOM generation, and SLSA supply chain integrity
- **DevSecOps Automation** -- SAST/DAST pipeline integration, secrets scanning, dependency analysis
- **Security QA** -- Test strategy, fuzzing, property-based testing, and coverage enforcement
- **Manual Security Review** -- Secure code review against CWE Top 25 and ASVS requirements
- **Final Quality Gate** -- Architecture compliance with /adversary integration for C2+ deliverables
- **Incident Response** -- Post-deployment IR runbooks, vulnerability lifecycle, and remediation tracking

---

## When to Use This Skill

Activate when:

- Designing a new system or service that requires security hardening
- Performing threat modeling on an architecture
- Implementing backend or frontend components with security requirements
- Setting up secure CI/CD pipelines and DevSecOps automation
- Writing security-focused test cases or fuzzing campaigns
- Conducting manual secure code review
- Creating incident response plans or runbooks
- Reviewing deliverables against security standards (OWASP, NIST, CIS, SLSA)
- Planning infrastructure with container security and supply chain integrity

---

## Available Agents

| Agent | Role | Output Location |
|-------|------|-----------------|
| `eng-architect` | Solution Architect and Threat Modeler | `projects/${JERRY_PROJECT}/engagements/{engagement-id}/eng-architect-{topic-slug}.md` |
| `eng-lead` | Engineering Lead and Standards Enforcer | `projects/${JERRY_PROJECT}/engagements/{engagement-id}/eng-lead-{topic-slug}.md` |
| `eng-backend` | Secure Backend Engineer | `projects/${JERRY_PROJECT}/engagements/{engagement-id}/eng-backend-{topic-slug}.md` |
| `eng-frontend` | Secure Frontend Engineer | `projects/${JERRY_PROJECT}/engagements/{engagement-id}/eng-frontend-{topic-slug}.md` |
| `eng-infra` | Secure Infrastructure Engineer | `projects/${JERRY_PROJECT}/engagements/{engagement-id}/eng-infra-{topic-slug}.md` |
| `eng-devsecops` | DevSecOps Pipeline Engineer | `projects/${JERRY_PROJECT}/engagements/{engagement-id}/eng-devsecops-{topic-slug}.md` |
| `eng-qa` | Security QA Engineer | `projects/${JERRY_PROJECT}/engagements/{engagement-id}/eng-qa-{topic-slug}.md` |
| `eng-security` | Security Code Review Specialist | `projects/${JERRY_PROJECT}/engagements/{engagement-id}/eng-security-{topic-slug}.md` |
| `eng-reviewer` | Final Review Gate and Quality Enforcer | `projects/${JERRY_PROJECT}/engagements/{engagement-id}/eng-reviewer-{topic-slug}.md` |
| `eng-incident` | Incident Response Specialist | `projects/${JERRY_PROJECT}/engagements/{engagement-id}/eng-incident-{topic-slug}.md` |

All agents produce output at three levels:
- **L0 (Executive Summary):** Accessible summary for non-technical stakeholders. Answers "What does this mean for the project?"
- **L1 (Technical Detail):** Implementation-focused content with specifics, code examples, and configuration guidance.
- **L2 (Strategic Implications):** Trade-offs, long-term risks, alignment with security posture, and architectural evolution.

---

## Invoking an Agent

### Option 1: Natural Language Request

Simply describe what you need:

```
"Design a secure microservice architecture with threat model"
"Review this API implementation for OWASP Top 10 vulnerabilities"
"Set up a DevSecOps pipeline with SAST and container scanning"
"Create an incident response runbook for credential compromise"
"Test this authentication flow with fuzzing and boundary testing"
```

The orchestrator selects the appropriate agent based on keywords and context.

### Option 2: Explicit Agent Request

Request a specific agent:

```
"Use eng-architect to create a threat model for the payment service"
"Have eng-devsecops design the CI/CD security pipeline"
"I need eng-security to review the authentication module"
```

### Option 3: Native Agent Invocation

Agents are registered via `plugin.json` and discovered by Claude Code automatically. The orchestrator invokes them as named subagents:

```python
Task(
    description="eng-architect: Threat model for payment service",
    subagent_type="eng-architect",
    prompt="""
## ENG CONTEXT (REQUIRED)
- **Engagement ID:** ENG-0042
- **Topic:** Payment Service Threat Model

## TASK
Produce a threat model for the payment service using STRIDE analysis
with DREAD risk scoring. Include architecture diagrams, trust boundaries,
data flow analysis, and prioritized threat matrix.
"""
)
```

Claude Code enforces the agent's `tools` frontmatter — eng-architect only has access to Read, Write, Edit, Glob, Grep, Bash, WebSearch, WebFetch and the Context7 MCP server.

---

## Orchestration Flow

### 8-Step Sequential Phase-Gate Workflow

The /eng-team skill follows
Files: 47
Size: 255.7 KB
Complexity: 66/100
Category: Design

Related in Design