advisory

Analyze architecture and code for security vulnerabilities using NIST, OWASP ASVS, and CWE frameworks.

Updated Aug 23, 2026
One-click install
npx skills add https://github.com/notchrisgroves/ia-framework --skill advisory
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: advisory
Source: https://github.com/notchrisgroves/ia-framework/tree/main/skills/advisory
Command: npx skills add https://github.com/notchrisgroves/ia-framework --skill advisory

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill provides expert security guidance, helping you identify and remediate vulnerabilities in your architecture and code, and offering strategic security advice.

Core Features & Use Cases

  • Architecture Review: Analyze system design, perform threat modeling (STRIDE/PASTA), and identify architectural security gaps.
  • Code Review: Scan source code for vulnerabilities using OWASP Top 10 and CWE classifications, providing secure coding examples.
  • Strategic Guidance: Offer best practices for security posture, compliance, and threat intelligence.
  • Use Case: A startup can use this Skill to get a security review of their new web application's architecture and code before launch, ensuring they build securely from the ground up.

Quick Start

Use the advisory skill to get security guidance on securing your API.

Frequently Asked Questions about advisory

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform threat modeling and architecture review for my application?

To perform threat modeling and architecture review, you need detailed architecture documentation. The process analyzes system design using STRIDE or PASTA frameworks to identify architectural security gaps and provide strategic remediation guidance.

Can I use this for code security analysis and vulnerability classification?

Yes, you can use it for code security analysis by providing source code access. It scans for vulnerabilities using OWASP Top 10 and CWE classifications, returning actionable secure coding examples to remediate identified issues.

What security frameworks are used for vulnerability analysis and compliance guidance?

Vulnerability analysis and compliance guidance utilize NIST, OWASP ASVS, and CWE frameworks. These frameworks classify vulnerabilities and offer best practices to improve your overall security posture and threat intelligence.

Do I need source code access to get a comprehensive security review?

Source code access is required for comprehensive code security analysis. Alternatively, providing detailed architecture documentation allows for strategic security advice, design reviews, and threat modeling without source code.

What is the best way to secure my API architecture before launch?

The best way to secure API architecture before launch is through a pre-launch design review. This scopes engagements for strategic security advice, performs threat modeling, and identifies architectural security gaps using structured frameworks.

When should I not use an advisory approach for security vulnerabilities?

An advisory approach should not be used when you lack detailed architecture documentation or source code access. Comprehensive vulnerability analysis and strategic security advice require these inputs to accurately scope the engagement.