You know you should "do security" but not where to start. This skill has a plain conversation about your business, then hands you a short, prioritized plan.
Already have a CISO and a SOC 2 in flight? Skip this. Staring at a security questionnaire with no idea where to start? Keep reading.
Findings explained in sentences a founder can read at 11pm — no acronym soup.
Vendors, contracts, who owns what — most real risk starts outside the codebase.
A pre-seed app doesn't need what a bank needs. It says what matters now, and what can wait.
BuildeRiot is a fictional startup we ran through the skill, so you see real output.
12 in place · 6 unverified · 8 need work.
What you do, who your customers are, what data you hold. No jargon required.
It scans your repo first, so it doesn't ask what it can already see.
Only the technical questions that apply to your stack.
A prioritized checklist and the dashboard shown above.
security-checklist.mdsecurity-dashboard.htmlA plain-English status report on one topic.
Fixes one item safely — with your approval.
Drafts the document a compliance item needs.
It runs inside your own Claude Code session and saves a plain HTML file to your project. No account, no server, no third party.
Claude Code skills live in ~/.claude/skills/ (every project) or .claude/skills/ (this project only).
git clone https://github.com/advaha91/security4builders.git \ ~/.claude/skills/security4builders
git clone https://github.com/advaha91/security4builders.git \ .claude/skills/security4builders
Then ask Claude Code: "help me do a security assessment."
Built by two builders, for builders who need a first security pass without a six-figure consulting engagement.