bmad-security-review

Identify security risks and produce threat models, gap assessments, and remediation backlogs.

67|11|Updated Oct 28, 2025
One-click install
npx skills add https://github.com/bacoco/BMad-Skills --skill bmad-security-review
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bmad-security-review
Source: https://github.com/bacoco/BMad-Skills/tree/main/.claude/skills/bmad-security-review
Command: npx skills add https://github.com/bacoco/BMad-Skills --skill bmad-security-review

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and assets (resource) components.

What problem does it solve?

This skill hardens designs and implementations with structured security reviews, threat modeling, and remediation planning, aligning security with delivery.

Core Features & Use Cases

  • Threat modeling: identify trust boundaries and risks.
  • Vulnerability assessment: inventory dependencies, misconfigurations, and controls.
  • Remediation backlog: translate findings into actionable backlog items for downstream skills.

Quick Start

Trigger phrases like "threat model" or "security review" to generate artifacts such as a threat model, security-gap assessment, and remediation backlog.

Frequently Asked Questions about bmad-security-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I identify security risks in my product design?

Threat modeling systematically identifies trust boundaries, attack vectors, and vulnerabilities in your architecture. This skill generates a structured threat model by analyzing your system design, data flows, and deployment pipeline to surface risks before implementation.

What should I include in a security review for compliance?

A security review inventories dependencies, misconfigurations, and security controls while assessing compliance requirements. This skill produces a security-gap assessment tied to your architecture decisions and compliance considerations, with findings prioritized for remediation.

How do I turn security findings into actionable backlog items?

Remediation planning translates security gaps into prioritized backlog items with assigned owners and acceptance criteria. This skill generates a remediation backlog from threat modeling and vulnerability assessment, ready for your delivery pipeline.

When should I conduct a security review in my deployment pipeline?

Security reviews are critical before deploying features or systems to production. This skill applies threat modeling and vulnerability assessment to features, systems, and deployment pipelines, verifying prerequisites like architecture decisions and test strategy.

Can I use security reviews for existing systems and new features?

Yes. This skill conducts threat modeling and vulnerability assessment across both new features and existing deployments. It works with your current architecture and data flows to identify and mitigate risks regardless of system maturity.

What compliance considerations does a security review cover?

Security reviews assess your system against compliance requirements relevant to your architecture and data handling. This skill integrates compliance considerations into threat modeling and gap assessment, producing findings aligned with your regulatory obligations.