mdcu-seg

Automates MDCU security governance with STRIDE threat models, IRP containment, and RSOP audits.

Updated Aug 27, 2026
One-click install
npx skills add https://github.com/iago-leal/skills --skill mdcu-seg
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: mdcu-seg
Source: https://github.com/iago-leal/skills/tree/main/mdcu-framework/mdcu-seg
Command: npx skills add https://github.com/iago-leal/skills --skill mdcu-seg

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Módulo mdcu-seg expands MDCU by providing structured security analysis and governance, including threat modeling, incident containment, and longitudinal auditing.

Core Features & Use Cases

  • Threat modeling with STRIDE analysis per component/flow.
  • Incident containment using the F0 protocol with RSOP integration.
  • Continuous auditing and RSOP-based governance to maintain regulatory alignment.

Quick Start

Execute the commands /mdcu-seg threat-model, /mdcu-seg incidente, or /mdcu-seg auditoria to start the corresponding security workflow.

Frequently Asked Questions about mdcu-seg

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate STRIDE threat modeling for software components and data flows?

You can automate STRIDE threat modeling by invoking the threat-model command, which generates structured threat models analyzing security risks per component and data flow. This provides systematic coverage of spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege threats.

What is the best way to structure an incident containment playbook for active security threats?

The best way to structure incident containment is using the F0 protocol, which generates IRP containment playbooks integrated with RSOP records. This ensures active incidents are systematically contained while maintaining governance alignment throughout the response process.

How do I maintain continuous security auditing and regulatory alignment?

You maintain continuous security auditing through an RSOP-based security audit regime that includes quarterly reviews. This longitudinal governance approach tracks compliance over time and updates RSOP records to ensure ongoing regulatory alignment.

Can I integrate threat modeling with my existing incident response and governance workflows?

Yes, threat modeling integrates with existing workflows by connecting STRIDE analysis to incident containment via the F0 protocol and RSOP-based governance. This unified approach links threat identification, active incident response, and continuous auditing into a cohesive security workflow.

What structured outputs should I expect from a security analysis and incident containment workflow?

You should expect three structured outputs: STRIDE threat models for component risk analysis, IRP containment playbooks for active incident response, and RSOP-based audit records for longitudinal governance and quarterly compliance reviews.

When do I need RSOP-based governance for security auditing?

You need RSOP-based governance when maintaining regulatory alignment through continuous auditing and quarterly reviews. This framework provides longitudinal tracking of security controls and ensures structured governance across threat modeling and incident containment processes.