canon-security-assessment

Generate a governed security-assessment packet capturing threats, risks, and evidence gaps.

1|Updated Mar 26, 2026
One-click install
npx skills add https://github.com/apply-the/canon --skill canon-security-assessment
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: canon-security-assessment
Source: https://github.com/apply-the/canon/tree/main/.agents/skills/canon-security-assessment
Command: npx skills add https://github.com/apply-the/canon --skill canon-security-assessment

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Generates a governed security-assessment packet for an existing system to capture threats, risks, mitigations, assumptions, and evidence gaps in a formal Canon artifact.

Core Features & Use Cases

  • Exposes the Canon security-assessment workflow as a governed run that can be started from your AI assistant.
  • Guides authors to collect bounded surface details, risk ratings, and evidence gaps into a complete packet for governance, review, and publication.
  • Use Case: A security team needs a bounded, auditable packet describing threats and controls for a sanctioned deployment.

Quick Start

Provide RISK, ZONE, and an authored input under canon-input to start the security-assessment run.

Frequently Asked Questions about canon-security-assessment

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate a formal security assessment packet for an existing system?

To generate a security assessment packet, provide RISK, ZONE, and authored input under canon-input to start the governed run. This captures threats, risks, mitigations, and evidence gaps into a formal artifact for governance and review.

What is a governed security assessment packet used for?

A governed security assessment packet is used to persist threats, risks, and contextual details for governance, review, and release. It captures structured sections like assessment scope, in-scope assets, trust boundaries, and evidence gaps for an existing system.

When do I need a threat model artifact with evidence gaps for governance?

You need a threat model artifact with evidence gaps when a bounded security brief exists and you must persist risks and contextual details for governance. It satisfies requirements for structured sections including assessment scope and trust boundaries for sanctioned deployments.

Can I use this security assessment workflow without a bounded security brief?

No, the security assessment workflow requires a bounded security brief to exist before you start. It applies specifically when you need to persist threats, risks, and contextual details for governance, review, and release.

What is the best way to document threats and controls for a sanctioned deployment?

The best way to document threats and controls is authoring via canon-input with the --system-context existing workflow. This generates a complete, auditable packet capturing risk ratings and evidence gaps for a sanctioned deployment.

Why does the security assessment require the --system-context existing workflow?

The security assessment requires the --system-context existing workflow because it generates packets for existing systems. This mandates authoring via canon-input to properly capture threats, risks, mitigations, and assumptions as a formal Canon artifact.