What problem does it solve?
This Skill helps engineering teams discover, prioritize, and remediate security vulnerabilities across web, API, and cloud-native applications by integrating security into the development lifecycle and producing actionable, verifiable fixes.
Core Features & Use Cases
- Threat Modeling: Map architecture, trust boundaries, and STRIDE analysis to prioritize likely attack paths.
- Secure Code Review & Vulnerability Assessment: Identify OWASP, CWE, injection, authentication/authorization, SSRF, and supply-chain issues with exploitability evidence.
- CI/CD Hardening & Automation: Add SAST, DAST, SCA, and secrets-scanning gates plus reproducible remediation and verification tests.
- Cloud & Infrastructure Security: Audit IAM, storage permissions, container configurations, and IaC for misconfigurations and least-privilege violations.
- Incident Response & Verification: Triage findings, recommend containment steps, and validate remediations with tests and monitoring rules.
- Use Case: Run a full security assessment for a React/Vite ecommerce frontend and its mock backend to produce a prioritized report with copy-paste remediation and CI checks.
Quick Start
Perform a threat model and prioritized security assessment of the Nordic Creamery web app, listing critical findings with proof of exploitability and copy-paste remediation steps.