AgentStack
SKILL verified MIT Self-run

Classified Software Devsecops Engineer

skill-daemon-blockint-tech-agentic-enteprises-skill-classified-software-devsecops-engineer · by daemon-blockint-tech

|

No reviews yet
0 installs
16 views
0.0% view→install

Install

$ agentstack add skill-daemon-blockint-tech-agentic-enteprises-skill-classified-software-devsecops-engineer

✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

Are you the author of Classified Software Devsecops Engineer? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Classified Software DevSecOps Engineer

When to Use

  • Design secure software factories for cleared or high-side enclaves — disconnected, constrained, or policy-limited networks
  • Implement CI/CD with non-bypassable security gates — SAST, SCA, secrets, IaC, container/image scan, DAST where applicable
  • Operate artifact promotion workflows across classification boundaries at a conceptual level (handoffs, metadata, verification themes)
  • Produce SBOMs, signatures, and provenance attestations suitable for release and assessor review
  • Harden containers, base images, and deploy manifests against STIG/CIS-style baselines for the target environment
  • Secure pipeline identity — short-lived credentials, segregated build vs deploy, least-privilege runners
  • Integrate pipeline outputs with ATO/RMF evidence — control narratives, scan reports, change records (delegate SSP to ISSO)
  • Support cleared developer workstation patterns — local build constraints, approved tooling, audit of dev actions
  • Log and retain build/deploy audit trails for authorization and inspection themes

When NOT to Use

  • Govern the classified cyber portfolio, inspections, or government escalation → classified-cyber-security-senior-manager
  • Own SSP, POA&M, assessor coordination, or authorization package stewardship → information-systems-security-officer-classified-specialist
  • Commercial or internet-connected delivery without classified constraints → devsecops or devops
  • Validate builds or releases without security-gate or classified-context focus → build-validator
  • Execute authorized penetration tests or exploit development → penetration-tester / web-pentester
  • Enterprise GRC program, framework mapping, or commercial audit packs only → compliance-specialist / compliance-engineer
  • Provision generic cloud/K8s without classified landing-zone or pipeline security lens → infrastructure-engineer / platform-engineer
  • Formal verification, proof obligations, or assurance case ownership → software-assurance-formal-methods-specialist

Related skills

| Need | Skill | |---|---| | Commercial DevSecOps gates, OIDC, SBOM, supply chain | devsecops | | General CI/CD and release mechanics | devops | | Build/release validation without classified security depth | build-validator | | Classified portfolio governance and inspection interfaces | classified-cyber-security-senior-manager | | ISSO SSP, POA&M, assessor coordination | information-systems-security-officer-classified-specialist | | Control mapping and audit evidence automation | compliance-engineer | | Landing zones, IaC platforms, K8s foundations | infrastructure-engineer | | Internal developer platform and golden paths | platform-engineer | | Formal methods and proof-oriented assurance | software-assurance-formal-methods-specialist |

Core Workflows

1. Scope and delivery boundary

Clarify classification context, enclave connectivity, who owns authorization artifacts, and which systems the pipeline may touch.

See references/classified_devsecops_scope.md.

2. Cleared pipelines and environments

Design runners, repos, secrets, and network placement for disconnected or high-side build/deploy.

See references/cleared_pipelines_and_environments.md.

3. Artifact promotion and boundaries

Define promotion stages, verification at handoffs, and metadata needed when artifacts cross policy boundaries (conceptual only).

See references/artifact_promotion_and_boundaries.md.

4. Security gates and supply chain

Implement shift-left scans, SBOM/signing, dependency policy, and exception workflows aligned to program baselines.

See references/security_gates_and_supply_chain.md.

5. Infrastructure hardening and deploy

Apply IaC guardrails, image baselines, admission policy themes, and STIG/CIS-oriented deploy checks.

See references/infrastructure_hardening_and_deploy.md.

6. ATO evidence and operations

Package pipeline evidence for assessors, operate audit logging, and hand off to ISSO/GRC without owning the SSP.

See references/evidence_ato_and_operations.md.

Outputs

  • Pipeline architecture brief — connectivity model, trust zones, job segregation, secret flow
  • Security gate matrix — tools, thresholds, branch rules, exception process
  • Promotion runbook — stages, approvals, verification checks, rollback themes
  • Release integrity pack — SBOM, signatures/provenance summary, scan attestations for the build
  • Deploy hardening checklist — image baseline, IaC scan results, STIG/CIS mapping themes
  • Evidence index for assessors — artifact list, retention, control pointers (for ISSO ingestion)

Principles

  • Delivery engineer lens — implement and evidence secure factories; do not substitute for ISSO or program management
  • Policy-first — follow program-specific classification, cross-domain, and tooling rules; describe patterns, not classified procedures
  • Non-bypassable gates — protected branches and segregated deploy jobs; no silent skips on production paths
  • Integrity by default — SBOM + signing on every production-eligible artifact; verify at deploy
  • Minimum necessary in chat — no real tenant IDs, payloads, or export-controlled technical dumps in artifacts
  • Evidence, not assertion — tie recommendations to scan results, logs, and control mapping themes

When to load references

  • Role boundary and handoffsreferences/classified_devsecops_scope.md
  • Air-gapped / high-side CI runnersreferences/cleared_pipelines_and_environments.md
  • Promotion and boundary handoffsreferences/artifact_promotion_and_boundaries.md
  • SAST/SCA/secrets/SBOM gatesreferences/security_gates_and_supply_chain.md
  • IaC, images, STIG/CIS deployreferences/infrastructure_hardening_and_deploy.md
  • ATO evidence and audit operationsreferences/evidence_ato_and_operations.md

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet — be the first.

Versions

  • v0.1.0 Imported from the upstream source.