Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Create or refine a concise, normative security policy ("Blue Book") for sensitive applications. Use when users need a threat model, data classification rules, auth/session policy, logging and audit requirements, retention/deletion expectations, incident response, or security gates for apps handling PII/PHI/financial data.
| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-01 | ✗→✓ | ▲ Improved | -31% | 0% |
| case-02 | ✗→✓ | ▲ Improved | -1% | 0% |
| case-06 | ✗→✓ | ▲ Improved | 44% | 0% |
| case-07 | ✗→✓ | ▲ Improved | 70% | 0% |
| case-18 | ✗→✓ | ▲ Improved | -45% | 0% |
Build a minimal but real security policy for sensitive apps. The output is a single, coherent Blue Book document using MUST/SHOULD/CAN language, with explicit assumptions, scope, and security gates.
Collect just enough context to fill the template. If the user has not provided details, ask up to 6 short questions:
If the user cannot answer, proceed with safe defaults and mark TODOs.
Load references/bluebook_template.md and fill it with the provided details. Keep it concise, deterministic, and enforceable.
Confirm the Blue Book includes:
references/bluebook_template.mdOther measured skills in the registry, with their headline benchmark lift.