enterprise-security
Central authority for Claude Code enterprise security. Covers enterprise managed policies (managed-settings.json), settings precedence hierarchy, policy file locations (macOS, Linux, Windows), unoverridable organizational policies, cloud execution security (isolated VMs, network access controls, credential protection), IDE security (VS Code, JetBrains), devcontainer security, and security best practices for teams. Assists with configuring enterprise policies, understanding precedence, and implementing organizational security standards. Delegates 100% to docs-management skill for official documentation.
What this skill does
# Enterprise Security Skill ## MANDATORY: Invoke docs-management First > **STOP - Before providing ANY response about Claude Code enterprise security:** > > 1. **INVOKE** `docs-management` skill > 2. **QUERY** for the user's specific topic > 3. **BASE** all responses EXCLUSIVELY on official documentation loaded > > **Skipping this step results in outdated or incorrect information.** ### Verification Checkpoint Before responding, verify: - [ ] Did I invoke docs-management skill? - [ ] Did official documentation load? - [ ] Is my response based EXCLUSIVELY on official docs? If ANY checkbox is unchecked, STOP and invoke docs-management first. --- ## Overview Central authority for Claude Code enterprise security. This skill uses **100% delegation to docs-management** - it contains NO duplicated official documentation. **Architecture:** Pure delegation with keyword registry. All official documentation is accessed via docs-management skill queries. ## When to Use This Skill **Keywords:** enterprise, managed-settings.json, enterprise managed policy, settings precedence, organizational policies, cloud execution security, IDE security, VS Code security, JetBrains security, devcontainer security, team security, audit logging, credential protection **Use this skill when:** - Configuring enterprise managed policies - Understanding settings precedence - Setting up organizational security standards - Configuring cloud execution security - Understanding IDE security considerations - Setting up devcontainer security - Implementing team security practices ## Keyword Registry for docs-management Queries Use these keywords when querying docs-management skill for official documentation: ### Enterprise Managed Policies | Topic | Keywords | | --- | --- | | Overview | "enterprise managed policy", "managed-settings.json" | | File Locations | "enterprise policy paths", "policy file locations" | | Precedence | "settings precedence", "enterprise policies precedence" | | Unoverridable | "unoverridable policies", "organizational restrictions" | ### Cloud Execution Security | Topic | Keywords | | --- | --- | | Overview | "cloud execution security", "isolated virtual machines" | | Network Controls | "network access controls", "cloud network security" | | Credentials | "credential protection", "cloud credential security" | | Branch Restrictions | "branch restrictions", "protected branches" | | Audit Logging | "audit logging", "security audit" | | Cleanup | "automatic cleanup", "cloud session cleanup" | ### IDE Security | Topic | Keywords | | --- | --- | | VS Code | "VS Code security", "IDE security VS Code" | | JetBrains | "JetBrains security", "IDE security JetBrains" | | IDE Context | "IDE-specific security", "extension security" | ### DevContainer Security | Topic | Keywords | | --- | --- | | Container Isolation | "devcontainer security", "container isolation" | | Security Features | "devcontainer security features", "container security" | | Integration | "devcontainer sandboxing", "container integration" | ### Security Best Practices | Topic | Keywords | | --- | --- | | Team Security | "team security", "organizational standards" | | Sensitive Code | "working with sensitive code", "security best practices" | | Reporting Issues | "reporting security issues", "HackerOne", "vulnerability disclosure" | ## Quick Decision Tree **What do you want to do?** 1. **Set up managed policies** -> Query docs-management: "enterprise managed policy", "managed-settings.json" 2. **Understand precedence** -> Query docs-management: "settings precedence", "enterprise policies precedence" 3. **Find policy file locations** -> Query docs-management: "enterprise policy paths", "policy file locations" 4. **Configure cloud security** -> Query docs-management: "cloud execution security", "isolated virtual machines" 5. **Understand IDE security** -> Query docs-management: "VS Code security", "JetBrains security" 6. **Set up devcontainer** -> Query docs-management: "devcontainer security", "container isolation" 7. **Follow best practices** -> Query docs-management: "team security", "security best practices" ## Topic Coverage ### Managed Policies Topics - managed-settings.json locations (macOS, Linux, Windows) - Settings precedence hierarchy - Unoverridable organizational policies - Policy enforcement mechanisms ### Cloud Security Topics - Isolated virtual machines - Network access controls - Credential protection - Branch restrictions - Audit logging - Automatic cleanup ### IDE Security Topics - VS Code extension security - JetBrains plugin security - IDE-specific security contexts ### DevContainer Topics - Container isolation benefits - Security features in devcontainer setup - Integration with sandboxing ### Best Practices Topics - Working with sensitive code - Team security standards - Reporting security issues (HackerOne) - Vulnerability disclosure ## Troubleshooting Quick Reference | Issue | Keywords for docs-management | | --- | --- | | Policy not applied | "enterprise managed policy", "settings precedence" | | Wrong precedence | "settings precedence", "enterprise policies precedence" | | Cloud security issues | "cloud execution security", "network access controls" | | IDE security concerns | "VS Code security", "JetBrains security" | | Container issues | "devcontainer security", "container isolation" | ## Related Skills - **sandbox-configuration** - For sandboxing and isolation - **permission-management** - For allow/deny/ask rules - **settings-management** - For general configuration ## Version History - **v1.0.0** (2025-11-30): Initial release (split from security-meta) - Focused on enterprise security only - Pure delegation architecture - Comprehensive keyword registry --- ## Last Updated **Date:** 2025-11-30 **Model:** claude-opus-4-5-20251101
Related in Cloud & DevOps
appbuilder-action-scaffolder
IncludedCreate, implement, deploy, and debug Adobe Runtime actions with consistent layout, validation, and error handling. Use this skill whenever the user needs to add actions to an App Builder project, understand action structure (params, response format, web/raw actions), configure actions in the manifest, use App Builder SDKs (State, Files, Events, database), deploy and invoke actions via CLI, debug action issues, or implement patterns such as webhook receivers, custom event providers, journaling consumers, large payload redirects, action sequence pipelines, and Asset Compute workers. Also trigger when users mention serverless functions in Adobe context, action logging, IMS authentication for actions, or cron-style scheduled actions.
orchestrating-datacloud
IncludedSalesforce Data Cloud product orchestrator for connect→prepare→harmonize→segment→act workflows. Use this skill when the user needs a multi-step Data Cloud pipeline, cross-phase troubleshooting, or data space and data kit management. TRIGGER when: user needs a multi-step Data Cloud pipeline, asks to set up or troubleshoot Data Cloud across phases, manages data spaces or data kits, or wants a cross-phase sf data360 workflow. DO NOT TRIGGER when: work is isolated to a single phase (use the matching phase-specific skill), the task is STDM/session tracing/parquet telemetry (use observing-agentforce), standard CRM SOQL (use querying-soql), or Apex implementation (use generating-apex).
github-project-automation
IncludedAutomate GitHub repository setup with CI/CD workflows, issue templates, Dependabot, and CodeQL security scanning. Includes 12 production-tested workflows and prevents 18 errors: YAML syntax, action pinning, and configuration. Use when: setting up GitHub Actions CI/CD, creating issue/PR templates, enabling Dependabot or CodeQL scanning, deploying to Cloudflare Workers, implementing matrix testing, or troubleshooting YAML indentation, action version pinning, secrets syntax, runner versions, or CodeQL configuration. Keywords: github actions, github workflow, ci/cd, issue templates, pull request templates, dependabot, codeql, security scanning, yaml syntax, github automation, repository setup, workflow templates, github actions matrix, secrets management, branch protection, codeowners, github projects, continuous integration, continuous deployment, workflow syntax error, action version pinning, runner version, github context, yaml indentation error
sf-datacloud
IncludedSalesforce Data Cloud product orchestrator for connect→prepare→harmonize→segment→act workflows. TRIGGER when: user needs a multi-step Data Cloud pipeline, asks to set up or troubleshoot Data Cloud across phases, manages data spaces or data kits, or wants a cross-phase `sf data360` workflow. DO NOT TRIGGER when: work is isolated to a single phase (use the matching sf-datacloud-* skill), the task is STDM/session tracing/parquet telemetry (use sf-ai-agentforce-observability), standard CRM SOQL (use sf-soql), or Apex implementation (use sf-apex).
fabric-cli
IncludedUse this skill for Fabric.so CLI workflows with the `fabric` terminal command: diagnose/install/login, search or browse a Fabric library, save notes/links/files, create folders, ask the Fabric AI assistant, manage tasks/workspaces, generate shell completion, check subscription usage, produce JSON output, and use Fabric as persistent agent memory. Do not use for Microsoft Fabric/Azure/Power BI `fab`, Daniel Miessler's Fabric framework, Python Fabric SSH, Fabric.js, or textile/fashion fabric.
lark
IncludedLark/Feishu CLI skills: lark-cli operations for docs, markdown, sheets, base, calendar, im, mail, task, okr, drive, wiki, slides, whiteboard, apps, approval, attendance, contact, vc, minutes, event. Use when the user needs to operate Lark/Feishu resources via lark-cli, send messages, manage documents, spreadsheets, calendars, tasks, OKRs, deploy web pages, or any Feishu/Lark workspace operations.