red-team

Execute structured adversarial testing across releases to uncover security weaknesses.

Updated Apr 21, 2026
One-click install
npx skills add https://github.com/brucebanner010198-commits/DevSecOps-Agency --skill red-team-brucebanner010198-commits
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: red-team
Source: https://github.com/brucebanner010198-commits/DevSecOps-Agency/tree/main/skills/red-team
Command: npx skills add https://github.com/brucebanner010198-commits/DevSecOps-Agency --skill red-team-brucebanner010198-commits

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Coordinated adversarial testing across releases to uncover security and process weaknesses before deployment.

Core Features & Use Cases

  • Threat-model-driven red-team engagements across projects
  • Reproduction pipelines, ADR linkage, and governance artifact creation
  • Use Case: Before shipping, run a quarterly adversarial sweep and prompt-change review to ensure defenses remain effective

Quick Start

Dispatch a pre-release red-team engagement to perform threat modeling, reproduce findings, and link ADRs.

Frequently Asked Questions about red-team

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is adversarial testing for pre-release validation?

Adversarial testing applies threat modeling and attack catalogs to uncover security and process weaknesses before deployment. It coordinates structured engagements across releases to validate defense effectiveness.

How do I run a red-team engagement for prompt changes?

Dispatch a pre-release red-team engagement to perform threat modeling, reproduce findings, and link ADRs. This enforces OWASP ASI mappings and updates governance artifacts for prompt changes.

When should I perform a quarterly portfolio sweep for security audits?

Perform a quarterly portfolio sweep to validate defenses across multiple projects and integrations. It coordinates adversarial testing across Chief, CRT, and allied councils to systematically uncover process weaknesses.

Can I use threat modeling with OWASP ASI mappings for new external integrations?

Yes, threat modeling with OWASP ASI mappings applies to new external integrations. The structured adversarial testing enforces these mappings alongside attack catalogs and reproduction pipelines to harden releases.

Does adversarial testing work with model-routing changes and ADR governance?

Adversarial testing explicitly supports model-routing changes by enforcing ladder and routing through ADRs and governance artifacts. It maps findings to OWASP ASI standards and reproduces attack scenarios.

What are the limitations of red-team adversarial testing for release hardening?

Red-team adversarial testing focuses on structured pre-release validation and quarterly sweeps but requires coordinated execution across councils. It does not replace continuous runtime monitoring or post-deployment incident response.