Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Workflow for authorized, evidence-preserving security review and remediation-task preparation.
.claude/skills/griddynamics-security-flow/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-07 | ✗→✓ | ▲ Improved | 186% | 0% |
| case-09 | ✗→✓ | ▲ Improved | 80% | 0% |
| case-10 | ✗→✓ | ▲ Improved | 157% | 0% |
| case-13 | ✗→✓ | ▲ Improved | 108% | 0% |
| case-15 | ✗→✓ | ▲ Improved | 131% | 0% |
<security_flow>
<description_and_purpose>
Run task-adaptive security review through mandatory canonical subagents. End with sanitized findings and concise inputs for later user-invoked coding flows.
</description_and_purpose>
<workflow_phases>
<prerequisites phase="0" applies="ALL">
load-project-context (required: all), orchestration (medium+), hitl (all, unless No HITL or Fully Autonomous).hitl skill.agents/TEMP/<FEATURE>/security-flow-state.md file; every phase updates it before the next starts.</prerequisites>
<subagent_policy required="true" inline_execution="prohibited">
subagent-directives.executor is never a gateway for full agents.</subagent_policy>
<readiness phase="1" applies="ALL" subagent="executor" role="Bounded security readiness and filename-only secret-gate operator" subagent_required_model="claude-haiku-4-5, gpt-5.4-low, gemini-3-flash, composer-2.5, gpt-5.6-luna" must-be-subagent>
executor to APPLY SKILL FILE phases/security-flow-readiness.md + inventory limited metadata/tools, run the filename-only secret gate, and return its gate state.PASS|NEEDS-HITL|STOP-HIGH-RISK|STOP-SCANNER-UNUSABLE.</readiness>
<authorize phase="2" applies="ALL" subagent="engineer" role="Enterprise security scope and authorization advisor" subagent_required_model="claude-sonnet-5, gpt-5.4-medium, gemini-3-flash, grok-4.5, gpt-5.6-terra" type="HITL" must-be-subagent>
engineer to APPLY SKILL FILE phases/security-flow-authorize.md + recommend scope, environment, exclusions, activities, tool/data-flow decisions, bounds, and stop conditions.hitl; unresolved material decisions block.</authorize>
<deterministic_gates phase="3" applies="development/change/PR/pipeline" subagent="executor" role="Bounded deterministic security-gate operator" subagent_required_model="claude-haiku-4-5, gpt-5.4-low, gemini-3-flash, composer-2.5, gpt-5.6-luna" must-be-subagent>
executor to APPLY SKILL FILE phases/security-flow-deterministic-gates.md + run approved deterministic gates and return unchanged findings with HIGH+|CLEAN|ERROR.HIGH+|CLEAN|ERROR.</deterministic_gates>
<model_and_select phase="4" applies="ALL" subagent="architect" role="Security architect mapping threats to complete contextual coverage" subagent_required_model="claude-opus-4-8, gpt-5.5-high, gemini-3.1-pro-high, gpt-5.6-sol" must-be-subagent>
architect to APPLY SKILL FILE phases/security-flow-model-and-select.md + build the threat model, map applicable areas/tools/exclusions, and return the complete authorized coverage plan.</model_and_select>
<inspect_and_test phase="5" applies="ALL" subagent="engineer" role="Security engineer producing bounded evidence by applicable area" subagent_required_model="claude-sonnet-5, gpt-5.4-medium, gemini-3-flash, grok-4.5, gpt-5.6-terra" must-be-subagent>
engineer to APPLY SKILL FILE phases/security-flow-inspect-and-test.md + inspect one assigned area bundle, run approved tools directly, and return evidence, findings, limitations, and anomalies.</inspect_and_test>
<normalize_and_triage phase="6" applies="ALL" subagent="executor" role="Lossless finding converter" subagent_required_model="claude-haiku-4-5, gpt-5.4-low, gemini-3-flash, composer-2.5, gpt-5.6-luna" required_followup_subagent="engineer" must-be-subagent>
executor to APPLY SKILL FILE phases/security-flow-normalize-and-triage.md STEP 6.1 + mechanically normalize source records and reconcile counts without inference.engineer to APPLY SKILL FILE phases/security-flow-normalize-and-triage.md STEP 6.2 + correlate, verify, disposition, and prioritize the normalized findings.</normalize_and_triage>
<independent_review phase="7" applies="ALL" subagent="reviewer" role="Independent security evidence and coverage reviewer" subagent_required_model="gpt-5.4-medium, gemini-3.1-pro-preview, claude-sonnet-5, grok-4.5, gpt-5.6-terra" must-be-subagent>
reviewer to APPLY SKILL FILE phases/security-flow-independent-review.md + independently audit coverage, evidence, safety, and conclusions; return acceptance or required corrections.</independent_review>
<report_and_package phase="8" applies="ALL" subagent="engineer" role="Security reporter and remediation-input designer" subagent_required_model="claude-sonnet-5, gpt-5.4-medium, gemini-3-flash, grok-4.5, gpt-5.6-terra" type="HITL" must-be-subagent>
engineer to APPLY SKILL FILE phases/security-flow-report-and-package.md STEP 8.1 + build sanitized report/run/findings and the proposed fix-similarity INDEX.hitl.engineer to APPLY SKILL FILE phases/security-flow-report-and-package.md STEP 8.3 + apply the approved INDEX and emit concise task-input files only.coding-flow.</report_and_package>
</workflow_phases>
<global_gates>
</global_gates>
<failure_handling>
</failure_handling>
<completion>
Complete only when required phases pass, sanitized outputs are returned or stored as approved, the task INDEX is approved/amended, and no downstream coding flow was started.
</completion>
</security_flow>
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | fail→fail | 10,248 | 13,180 | +29% | 1 | 1 | 0% | 1,307 | 4,115 | +215% | 0 | 0 | — |
case-02 | fail→fail | 20,369 | 9,810 | -52% | 1 | 1 | 0% | 2,401 | 3,688 | +54% | 0 | 0 | — |
case-03 | fail→fail | 21,180 | 10,771 | -49% | 1 | 1 | 0% | 2,436 | 3,831 | +57% | 0 | 0 | — |
case-04 | fail→fail | 16,752 | 12,328 | -26% | 1 | 1 | 0% | 1,197 | 3,902 | +226% | 0 | 0 | — |
case-05 | pass→pass | 11,658 | 19,942 | +71% | 1 | 1 | 0% | 2,080 | 6,231 | +200% | 0 | 0 | — |
case-06 | pass→pass | 6,015 | 7,941 | +32% | 1 | 1 | 0% | 520 | 3,380 | +550% | 0 | 0 | — |
case-07 | fail→pass | 9,607 | 8,684 | -10% | 1 | 1 | 0% | 1,460 | 4,172 | +186% | 0 | 0 | — |
case-08 | pass→pass | 8,871 | 5,289 | -40% | 1 | 1 | 0% | 1,207 | 3,261 | +170% | 0 | 0 | — |
case-09 | fail→pass | 13,298 | 14,893 | +12% | 1 | 1 | 0% | 1,838 | 3,306 | +80% | 0 | 0 | — |
case-10 | fail→pass | 22,908 | 2,214 | -90% | 1 | 1 | 0% | 1,184 | 3,048 | +157% | 0 | 0 | — |
case-11 | pass→pass | 9,659 | 2,507 | -74% | 1 | 1 | 0% | 1,498 | 3,130 | +109% | 0 | 0 | — |
case-12 | pass→pass | 8,046 | 1,578 | -80% | 1 | 1 | 0% | 1,210 | 2,985 | +147% | 0 | 0 | — |
case-13 | fail→pass | 13,031 | 8,784 | -33% | 1 | 1 | 0% | 1,988 | 4,133 | +108% | 0 | 0 | — |
case-14 | pass→pass | 7,159 | 5,323 | -26% | 1 | 1 | 0% | 936 | 3,640 | +289% | 0 | 0 | — |
case-15 | fail→pass | 9,692 | 2,715 | -72% | 1 | 1 | 0% | 1,371 | 3,162 | +131% | 0 | 0 | — |
case-16 | fail→pass | 12,922 | 4,813 | -63% | 1 | 1 | 0% | 1,958 | 3,512 | +79% | 0 | 0 | — |
case-17 | fail→pass | 11,837 | 5,514 | -53% | 1 | 1 | 0% | 1,703 | 3,517 | +107% | 0 | 0 | — |
case-18 | pass→pass | 14,134 | 4,560 | -68% | 1 | 1 | 0% | 2,027 | 3,368 | +66% | 0 | 0 | — |
case-19 | pass→pass | 8,866 | 3,985 | -55% | 1 | 1 | 0% | 1,345 | 3,387 | +152% | 0 | 0 | — |
case-20 | fail→pass | 5,658 | 4,135 | -27% | 1 | 1 | 0% | 880 | 3,483 | +296% | 0 | 0 | — |
case-21 | fail→pass | 7,451 | 2,110 | -72% | 1 | 1 | 0% | 1,192 | 3,088 | +159% | 0 | 0 | — |
case-22 | pass→pass | 12,249 | 4,181 | -66% | 1 | 1 | 0% | 1,810 | 3,421 | +89% | 0 | 0 | — |
case-23 | fail→pass | 5,168 | 2,982 | -42% | 1 | 1 | 0% | 779 | 3,230 | +315% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 23 cases were attempted, and 22 counted toward the lift figure. The other 1 produced results that are not comparable between the two arms, so they are excluded from the headline rather than averaged into it. The headline lift of +43 percentage points is the difference between those two pass rates over the 22 comparable cases.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.