application-security

Assess web applications and APIs for security weaknesses across the SDLC.

Updated May 22, 2026
One-click install
npx skills add https://github.com/drupadsachania/aegis-skills --skill application-security-drupadsachania
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: application-security
Source: https://github.com/drupadsachania/aegis-skills/tree/main/skills/application-security
Command: npx skills add https://github.com/drupadsachania/aegis-skills --skill application-security-drupadsachania

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Systematically assess web applications and APIs for security weaknesses across the full SDLC.

Core Features & Use Cases

  • Threat modelling across data flows to identify STRIDE-based risks.
  • Integrated SAST/DAST guidance, dependency auditing, API security reviews, and security testing planning.
  • Guidance for pre-release security reviews and remediation planning aligned to OWASP Top 10, MITRE ATT&CK, and NIST SSDF.

Quick Start

Load the threat-modeling-appsec phase to begin the risk assessment workflow.

Frequently Asked Questions about application-security

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform threat modeling for web applications and APIs?

Threat modeling for web apps and APIs systematically identifies STRIDE-based risks across data flows. This Skill provides phase-based workflows to map security threats and assess weaknesses across the full software development lifecycle.

What is the best way to integrate SAST and DAST reviews into the SDLC?

Integrated SAST and DAST reviews strengthen application security by detecting code and runtime vulnerabilities early. This Skill guides dependency auditing and security testing planning aligned with OWASP Top 10 and NIST SSDF frameworks.

Can I use this for API security hardening aligned with OWASP Top 10?

Yes, API security hardening aligns directly with OWASP Top 10 and MITRE ATT&CK frameworks. This Skill assesses API weaknesses and guides remediation planning to mitigate enterprise security risks effectively.

How do I conduct a pre-release security assessment for enterprise web apps?

Pre-release security assessments for enterprise web apps evaluate vulnerabilities before deployment. This Skill supports phase-based workflows for threat modeling, dependency auditing, and remediation planning aligned to NIST SSDF standards.

Does this security assessment workflow support MITRE ATT&CK mapping?

Security assessment workflows support MITRE ATT&CK mapping to identify adversary tactics and techniques. This Skill aligns threat modeling and security testing with ATT&CK, OWASP Top 10, and NIST SSDF for comprehensive risk coverage.