Hi - I answer from the OpenSmartRoute documentation: routing, the API, plans and quotas, self-hosting. Ask away, or open a support ticket if you need a person.
Grounded in the docs - follow a source before acting on it.
tapps-domain-security - Skill - OpenSmartRoute
Skillv1.0.0
tapps-domain-security
Security-focused TAPPS workflow: playbook, library docs, security scan, and CVE check. Use when implementing auth, secrets, input validation, or pre-release security passes.
Imported from wtthornton/agentforge-sinks-plugin (.tapps-mcp/backups/2026-08-03-200957/.claude/skills/tapps-domain-security/SKILL.md). Install upstream with npx skills add wtthornton/agentforge-sinks-plugin --skill tapps-domain-security. Copyright stays with the author.
Domain playbook workflow — same quality gate as the standard TAPPS pipeline.
Session bootstrap. Call tapps_session_start() if not already called this session.
Load playbook. Call tapps_domain_playbook(domain="security") (or read bundled checklist from the response). Follow its workflow and checklist.
Library docs. For each entry in lookup_hints, call tapps_lookup_docs(library=..., topic=...) before using those APIs.
Domain tools. Run the tools listed in recommended_tools on changed files in scope.
Edit loop. After each Python file change, call tapps_quick_check(file_path=...).
4b. Run tapps_security_scan on sensitive changed files.
4c. Run tapps_dependency_scan when lockfiles or dependencies changed.
Close out. Invoke /tapps-finish-task with the task_type=security. Do not declare done without validate + checklist.
Use it
Copy one of these into your project. Installing also returns the manifest and these snippets.
# after Install: the listing is in your workspace's routing pool - a plan picks it for its slot
curl -s -X POST https://api.opensmartroute.ai/api/v1/route -H 'Authorization: Bearer $OSR_API_KEY' -H 'Content-Type: application/json' -d '{"text": "...", "plan": true}'
Installed into a catalogue, chosen by a router
Install tapps-domain-security and it becomes one more candidate the router can pick - when it fits.
A listing is a routing target with a manifest: what it does, which domains it covers, what it costs and who publishes it. Once installed it sits beside your own models and tools, is scored like any other candidate for each request, and shows up in the trace when it wins. Ratings come from workspaces that installed it, one per account.