007

Audit software projects across code, APIs, infrastructure, and CI/CD pipelines.

Updated Aug 27, 2026
One-click install
npx skills add https://github.com/ProgramadorBrasil/antigravity-skills --skill 007
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: 007
Source: https://github.com/ProgramadorBrasil/antigravity-skills/tree/main/skills/007
Command: npx skills add https://github.com/ProgramadorBrasil/antigravity-skills --skill 007

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

Software security often fails due to ad-hoc reviews, lack of threat modeling, and inconsistent hardening practices. This Skill provides a rigorous six-phase workflow to identify, assess, and mitigate risks across code, configurations, and infrastructure to raise security posture.

Core Features & Use Cases

  • Comprehensive threat modeling (STRIDE/PASTA) and security checklists for code, APIs, and infrastructure.
  • Incident response readiness with Red/Blue team playbooks and scoring to guide hardening and governance.
  • Centralized references and playbooks for rapid response and compliance alignment.

Quick Start

Run a full-audit against your project directory to generate a security-verified report and scoring.

Frequently Asked Questions about 007

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a security audit on my software project?

To perform a security audit, this Skill runs a six-phase workflow: surface mapping, threat modeling, checklist validation, red/blue playbooks, scoring, and final verdict. It reviews code, APIs, infrastructure, and CI/CD pipelines to generate a security-verified report.

What is threat modeling and how does it apply to hardening software?

Threat modeling identifies potential security risks using frameworks like STRIDE or PASTA. This Skill applies threat modeling to code, APIs, and infrastructure, creating structured checklists and red/blue team playbooks to guide software hardening and improve incident resilience.

Can I use this to improve incident response readiness for my CI/CD pipelines?

Yes, you can improve incident response readiness for CI/CD pipelines using the included Red/Blue team playbooks. The Skill evaluates pipeline configurations and infrastructure, providing scoring and governance guidance to raise your security posture and incident resilience.

What's the best way to ensure compliance alignment across modern software stacks?

The best way to ensure compliance alignment is through a rigorous audit workflow with centralized references and playbooks. This Skill enforces consistent hardening practices and security checklists across modern stacks, evaluating code and infrastructure to maintain compliance.

Does this security audit require any external security tools or dependencies?

No external security tools or dependencies are required to run this audit. The Skill operates independently using its own scripts and references to execute the six-phase process, mapping your attack surface and generating a final security score and verdict.