prd-security-analysis

Generates security-augmented chapters for user-submitted PRDs using STRIDE, GDPR, CCPA, APP, COPPA, encryption, authentication, and testing scenarios.

1|Updated Apr 3, 2026
One-click install
npx skills add https://github.com/timywel/prompt-lab --skill prd-security-analysis
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: prd-security-analysis
Source: https://github.com/timywel/prompt-lab/tree/main/skills/prd-security-analysis
Command: npx skills add https://github.com/timywel/prompt-lab --skill prd-security-analysis

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

PRD 安全分析扩展:为 PRD 自动补充威胁建模、隐私合规、数据加密、API 鉴权、安全测试等安全章节。自动触发:PRD 涉及登录/支付/用户数据/加密等功能时。

Core Features & Use Cases

  • Threat modeling based on STRIDE for security-sensitive features
  • Privacy compliance mapping to GDPR, CCPA, APP, COPPA and other regulatory frameworks
  • Data encryption and API authentication recommendations
  • Sensitive information handling guidelines and security testing scenarios
  • Auto-integration with prd-orchestrator and dynamic enhancement phase

Quick Start

Provide the PRD content or path and request an automatically generated security-augmented PRD chapter.

Frequently Asked Questions about prd-security-analysis

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I add threat modeling to a PRD for authentication and payment features?

To add threat modeling to a PRD, the skill applies STRIDE methodology to authentication and payment features, identifying structured security threats. It delivers an augmented PRD chapter with specific security testing scenarios and sensitive data handling guidelines.

What is the best way to ensure privacy compliance for GDPR and CCPA in product requirements?

Ensuring privacy compliance for GDPR and CCPA involves mapping PRD requirements to relevant regulatory frameworks. The skill automatically generates compliance mappings, embedding data encryption recommendations and privacy guidelines directly into the product requirements document.

Can I automatically generate security testing scenarios from a product requirements document?

Yes, you can generate security testing scenarios by providing the PRD content or file path. The skill analyzes security-sensitive functions like APIs and user data handling, outputting structured testing scenarios and encryption recommendations.

Does this PRD security analysis tool support API authentication and encryption recommendations?

Yes, this PRD security analysis supports API authentication and data encryption recommendations. It identifies sensitive information handling needs within the PRD and augments the document with structured security guidelines.

When do I need to run STRIDE threat modeling on my PRD?

You need STRIDE threat modeling when a PRD involves security-sensitive features like login, payments, user data, or encryption. The analysis can auto-trigger during orchestration to harden product design before implementation begins.

How to integrate security analysis chapters into an existing PRD workflow?

To integrate security analysis chapters, provide the PRD content to trigger automatic augmentation during the dynamic enhancement phase. The skill auto-integrates with prd-orchestrator to append threat modeling, compliance mappings, and testing scenarios.