bitwarden-security-context

作者: bitwarden

Bitwarden的安全原則(P01-P06)、安全詞彙與資料分類標準。當需要任何基礎安全背景資訊時使用…

npx skills add https://github.com/bitwarden/ai-plugins --skill bitwarden-security-context

Bitwarden Security Context

Quick-reference for Bitwarden's foundational security framework. Use this for security context during development, code review, or security analysis without loading the full threat-modeling or architecture-review skills.

Security Principles (P01-P06)

These six principles form the foundation for all security decisions at Bitwarden.

PrincipleNameCore Guarantee
P01Servers are Zero KnowledgeBitwarden infrastructure cannot access unencrypted user data. The server must not enable weakening of user-chosen protections, masquerade server data as user-encrypted content, or access encrypted data outside the client context.
P02A Locked Vault is SecureHighly sensitive vault data cannot be accessed in plaintext once the vault is locked, even if the device is compromised after locking. Platform limitations (e.g., JS memory) are mitigated through buffer clearing and available security features.
P03Limited Security on Semi-Compromised DevicesFor unlocked vaults on devices with userspace malware (but intact OS/kernel), clients maximize kernel/OS-level protections and balance security with usability through controls like biometrics.
P04No Security on Fully Compromised SystemsBitwarden cannot guarantee vault protection when hardware or OS-level integrity is fully compromised. This applies to unlocked vaults only — locked vaults are covered by P02.
P05Controlled Access to Vault DataVault data, whether at rest or in use, is accessible only to authorized parties under the user's explicit control. Isolation mechanisms are critical in high-risk environments like web browsers.
P06Minimized Impact of Security BreachesLimit breach scope and duration through session invalidation, key rotation (countering "harvest now, decrypt later"), and post-compromise security (new data remains protected after a breach).

Controlled Exceptions

Principles have documented exceptions. Known examples:

  • P01 — Key Connector: Self-hosted SSO without passwords. The server holds encryption keys on behalf of the user.
  • P01 — Icons Service: Plaintext domain names are sent to retrieve favicons.

Full documentation: Security Principles

Security Vocabulary

Standard terminology for security discussions at Bitwarden.

TermDefinition
Vault DataA user's private information stored in Bitwarden (passwords, usernames, secure notes, credit cards, identities, attachments)
Protected DataData stored in unreadable format (typically encrypted) with expectations about secure key storage
Data at RestStored data not actively used or transmitted (disk storage on devices or servers)
Data in UseData actively being processed or accessed, held in volatile memory
Data in TransitData actively transferred between locations, processes, or devices
Secure ChannelA communication channel providing confidentiality (unreadable to unauthorized parties) and integrity (tamper-proof)
Trusted ChannelA secure channel that also provides authenticity (verified identities of communicating parties)
Data ExportingControlled process where data leaves Bitwarden unprotected, nullifying security guarantees. Requires informed consent.
Data SharingControlled data exchange within the Bitwarden secure environment (security guarantees maintained)
Data LeakingUnintentional departure of data from Bitwarden unprotected
Bitwarden Secure EnvironmentAny process or application adhering to Bitwarden's security standards

Full documentation: Security Definitions

Security Requirements by Category

CategoryScopeKey Obligations
VDVault DataProtected at rest (encrypted with UserKey), allowed in use (decrypted during unlock), trusted channels in transit, export requires informed consent
EKEncryption Keys256-bit security strength, protected at rest and in transit, must never be exported
ATAuthentication TokensProtected storage at rest, mandatory transit protection
SCSecure ChannelsConfidentiality, integrity, replay prevention, forward secrecy for long-lived channels
TCTrusted ChannelsSecure channel properties plus receiver identity verification

Full documentation: Security Requirements

Architecture Decision Records (ADRs)

Bitwarden's accepted architecture decisions are catalogued separately from the security principles above. See ${CLAUDE_PLUGIN_ROOT}/references/adr-alignment.md for how security assessments should check alignment against them.

來自 bitwarden 的更多技能

figma-to-angular
bitwarden
此技能可將 Figma 設計規格轉換為 Bitwarden Clients 單一儲存庫中,具備 Storybook 故事的完整 Angular 元件。輸出結果應在視覺上符合設計,同時遵循所有程式碼庫慣例。
force-multiplier
bitwarden
將單一意圖同時套用於多個目標——例如 Bitwarden 生態系中的一組儲存庫,或單一 monorepo 內的多個專案——以 N 個一致的操作來執行,…
analyzing-git-sessions
bitwarden
分析指定時間範圍或提交範圍內的 Git 提交與變更,提供結構化摘要,適用於程式碼審查、回顧會議、工作日誌或工作階段…
coordinating-cross-team-breakdown
bitwarden
協調跨團隊審查與簽核 Bitwarden 技術分解。用於識別受影響團隊、建立第三部分簽核表格、追蹤…
assessing-jira-issue-relevance
bitwarden
當使用者提供單一Jira議題金鑰,並詢問該議題是否仍相關、仍適用、仍待處理、仍是錯誤、已修復,或可否……時使用。
assessing-test-coverage
bitwarden
用於判斷特定變更(PR、Jira key、Tech Breakdown 文件、Testmo CSV、變更路徑或具名……)已存在哪些測試覆蓋範圍時使用。
retrospecting
bitwarden
對 Claude Code 工作階段進行全面分析,檢視 Git 歷史記錄、對話日誌、程式碼變更,並收集使用者回饋以產生…
reviewing-incremental-changes
bitwarden
在重新審視已有評論的PR,或回應開發者在初次審查後的變更時,使用此技能。適用於存在PR討論串或…的情況。