What problem does it solve?
Individual vulnerability patches often leave the underlying architectural weaknesses untouched, so the same class of security failure recurs. This Skill turns vulnerability disclosures, supplied findings, incident documents, source code, or completed Codex Security scans into a decision-ready portfolio of structural and architectural hardening options with explicit tradeoffs.
Core Features & Use Cases
- Opportunity Analysis: Clusters evidence by violated invariants, trust boundaries, and control ownership to identify high-leverage structural improvements, or honestly concludes that local remediation is preferable.
- Option Development with Tradeoffs: Produces meaningfully different design alternatives with before-and-after Mermaid diagrams, delta tables, and assessments across security, performance, memory, reliability, operability, and migration dimensions.
- Structured Artifacts: Writes a distributable portfolio (hardening.md, hardening.json, per-opportunity proposals, diagrams) and an implementation handoff plan once an option is selected.
- Use Case: After a Codex Security scan reports several findings sharing a common root cause, use this Skill to generate a design-review-ready proposal comparing a baseline local-guards fix against a centralized enforcement boundary, complete with residual risk analysis and a migration plan.
Quick Start
Use the propose-security-hardening skill to analyze the findings in this scan directory and produce a hardening proposal portfolio with design options and tradeoffs.