From 3c754b805d1391ff263680796e5c8d4e96742b01 Mon Sep 17 00:00:00 2001 From: Edward Delaporte Date: Tue, 29 Sep 2026 16:04:45 -0500 Subject: [PATCH 1/2] Update README for recent updates * Add `code-cost` * Clarify intended audience - those who maintain automation that serves the mission of the University of Illinois * Add lesson recently learned - Code Risk Discussion engagements catch issues that these "skills" cannot. --- README.md | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/README.md b/README.md index c8f117b..7885909 100644 --- a/README.md +++ b/README.md @@ -20,12 +20,12 @@ for information about our development standards. ### Cybersecurity Review -- SecDev maintains an AI "skill", `/cybersecurity-review` for identifying vulnerabilities in local source code. -- We update this AI skill after OWASP updates the OWASP Top Ten, roughly every four years. -- This skill is intended to guide remediation efforts and is not a substitute for a mature Software Development Lifecycle. +- The Cybersecurity Development team at the University of Illinois maintains these AI "skills", `/code-risk` and `/code-cost` for identifying possible vulnerabilities and maintenance costs in local source code. +- We update this AI "skill" after OWASP updates the OWASP Top Ten, roughly every four years. +- This "skill" is intended to guide remediation efforts and is not a substitute for a mature Software Development Lifecycle, and Code Risk Discussion engagements for sensitive code. - We consider this skill suitable for exploration and education. - We want to help interpret and respond to these reports - they can be confusing, may contain false positives, and will raise questions. -- Campus IT Professionals can contact securitysupport@illinois.edu. +- Campus faculty and staff responsible for custom code supporting campus users can contact securitysupport@illinois.edu for assistance. ## Installation From a5f9c2fe2baf8ef267290daa3201d74776fca24e Mon Sep 17 00:00:00 2001 From: Edward Delaporte Date: Tue, 29 Sep 2026 16:08:22 -0500 Subject: [PATCH 2/2] Add link to Code Risk Discussion guide --- README.md | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/README.md b/README.md index 7885909..93cfb42 100644 --- a/README.md +++ b/README.md @@ -22,9 +22,10 @@ for information about our development standards. - The Cybersecurity Development team at the University of Illinois maintains these AI "skills", `/code-risk` and `/code-cost` for identifying possible vulnerabilities and maintenance costs in local source code. - We update this AI "skill" after OWASP updates the OWASP Top Ten, roughly every four years. -- This "skill" is intended to guide remediation efforts and is not a substitute for a mature Software Development Lifecycle, and Code Risk Discussion engagements for sensitive code. +- This "skill" is intended to guide remediation efforts and is not a substitute for a mature Software Development Lifecycle. - We consider this skill suitable for exploration and education. - We want to help interpret and respond to these reports - they can be confusing, may contain false positives, and will raise questions. +- We recommend also requesting a [Code Risk Discussion](https://answers.uillinois.edu/illinois/106153) engagement for more sensitive code, as we find that Code Risk Discussions catch issues that these "skills" cannot. - Campus faculty and staff responsible for custom code supporting campus users can contact securitysupport@illinois.edu for assistance. ## Installation