BlameJS
Official@blamejs
Because when something breaks, blame should know exactly where it lives. We own the stack so you don't have to chase the fault across an ecosystem.
Agent Skills by BlameJS
Showing 51 vetted skills indexed across 1 GitHub repositories.
dlp-gap-analysis
Identify DLP coverage gaps across AI-era exfiltration channels.
log-injection-telemetry
Sanitize CR/LF injection and redact secrets across telemetry pipelines.
rag-pipeline-security
Assess RAG pipeline security risks and map them to MITRE ATLAS TTPs.
audit-log-integrity
Assess audit logging controls for resistance to privileged attacker tampering.
threat-modeling-methodology
Enumerate AI threats and map them to ATLAS, ATT&CK, CWE, and CVE catalogs.
policy-exception-gen
Generate auditor-ready policy exception documents mapping residual threats to MITRE TTPs.
ai-attack-surface
Assess AI/ML attack surfaces mapped to MITRE ATLAS v2026.06.
coordinated-vuln-disclosure
Audit coordinated vulnerability disclosure programs for regulatory compliance and AI vulnerability handling.
ot-ics-security
Assess OT/ICS security posture with Purdue asset inventory and IEC 62443 scoring.
idp-incident-response
Run a 10-phase IdP tenant compromise assessment with jurisdiction clock tracking.
framework-gap-analysis
Analyze compliance framework controls against current attacker TTPs to produce structured gap declarations.
age-gates-child-safety
Map age assurance and child safety controls across 25+ global regulatory regimes.
supply-chain-integrity
Audit software and AI supply chains against mid-2026 attack patterns.
sector-financial
Map mid-2026 financial cyber threats to regulatory controls across 35+ jurisdictions.
mail-server-hardening
Audit SMTP, IMAP, POP3, ManageSieve, and mailbox-DAV listeners for protocol-layer security gaps.
privacy-consent-ops
Audit sanctions screening, consent management, DSR erasure, and ROPA workflows for operational integrity gaps.
zeroday-gap-learn
Map CVE attack vectors to MITRE ATLAS TTPs and assess framework control gaps.
vc-wallet-trust
Audit verifier trust controls for credential acceptance workflows.
pqc-first
Enforce post-quantum cryptography standards and analyze compliance gaps across security frameworks.
mcp-agent-trust
Enumerate MCP trust boundary failures and assess compliance gaps.
threat-model-currency
Score organizational threat models against a 14-class mid-2026 threat checklist.
cloud-security
Map cloud and AI workload threats to compliance controls for AWS, Azure, and GCP.
sector-federal-government
Map cybersecurity compliance gaps against federal and allied frameworks for 2026 threats.
identity-assurance
Assess identity assurance gaps across AAL/IAL/FAL, MFA, and OAuth/JWT controls.
Frequently Asked Questions About BlameJS
FAQPage SchemaWhat specific security tasks does BlameJS enable?▼
BlameJS enables precise identification of security gaps across RAG pipelines, cloud IAM, and OT/ICS environments. It facilitates threat modeling against MITRE ATLAS and ATT&CK, generates regulatory compliance artifacts for the EU AI Act and ISO/IEC 42001, and provides RWEP-based exploit prioritization for vulnerability management.
Which technical personas benefit from these capabilities?▼
Security architects, GRC analysts, and cloud infrastructure engineers utilize these capabilities to bridge the gap between high-level regulatory requirements and granular technical controls. It is designed for teams managing complex, multi-jurisdictional attack surfaces who require evidence-based security posture validation.
What are the prerequisites for implementing these security assessments?▼
Implementation requires access to existing telemetry pipelines, cloud provider IAM configurations, and current threat model documentation. Users must provide environment-specific metadata to map findings against the relevant MITRE frameworks and regulatory catalogs supported by the platform.