2-security-critique

Review SECURITY_PLAN.md findings, remove false positives, and generate a ranked backlog.

1|Updated Feb 10, 2026
One-click install
npx skills add https://github.com/opsMachine/OM-Agency --skill 2-security-critique
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: 2-security-critique
Source: https://github.com/opsMachine/OM-Agency/tree/main/skills/2-security-critique
Command: npx skills add https://github.com/opsMachine/OM-Agency --skill 2-security-critique

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Phase 2 red team critique addresses the need to validate and strengthen security findings from Phase 1 by eliminating false positives, surfacing missed risks, and organizing work for Phase 3.

Core Features & Use Cases

  • False positive elimination: Flag items that are not actually exploitable and prune the backlog.
  • Risk augmentation: Add missing risks and context to each finding.
  • Ranked backlog generation: Produce a prioritized list for Phase 3 to act upon.
  • Use Case: After Phase 1, run this skill to deliver a ranked backlog that guides remediation focus and resource allocation.

Quick Start

After Phase 1 completes, invoke '/2-security-critique' to produce a ranked backlog for Phase 3.

Frequently Asked Questions about 2-security-critique

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I refine a security audit backlog to remove false positives?

Refine a security audit backlog by reviewing initial findings, flagging items that are not actually exploitable, and pruning the backlog to eliminate false positives before prioritization.

What is red team critique in security findings?

Red team critique is a validation process that strengthens security findings by eliminating false positives, surfacing missed risks, and organizing the remaining backlog for remediation.

How do I generate a ranked backlog for security remediation?

Generate a ranked backlog by reviewing Pending items in your security plan, adding context to each finding, and producing a prioritized list to guide remediation focus and resource allocation.

When do I need to run a security critique on my findings?

Run a security critique after your initial Phase 1 security review completes to validate findings, add missed risks, and prepare a prioritized backlog for Phase 3 remediation planning.

Can I augment missed risks during security backlog refinement?

Yes, you can augment missed risks during backlog refinement by adding missing security vulnerabilities and context to existing findings before generating the final prioritized list.