What problem does it solve?
This Skill helps teams assess the security and privacy risks of an application without relying on improvised AI analysis or ungrounded legal conclusions. It coordinates a server-enforced threat-modeling workflow and produces cited research support that clearly separates confirmed findings, unresolved questions, and regulatory applicability limits.
Core Features & Use Cases
- STRIDE threat modeling: Runs a server-enforced workflow that identifies per-component threats, affected assets, severity, mitigations, and relevant regulatory citations.
- LINDDUN privacy analysis: Models privacy threats across personal-data flows, including potential harms and mitigations.
- Dependency and regulatory screening: Checks named dependencies against live CVE, CISA KEV, and FIRST EPSS data, and evaluates selected GDPR, NIS2, Cyber Resilience Act, and AI Act obligations using citations from official sources.
- Safe, transparent deliverables: Requires architecture-level user confirmation, avoids file and secret uploads, distinguishes retrieval failures from no-match results, and never presents the output as legal advice, a compliance verdict, a penetration test, or a code audit.
- Use Case: A team launching an AI-enabled SaaS product can describe its architecture, data flows, dependencies, deployment context, and legal posture, then receive a cited security review with workflow reports, vulnerability exposure results, regulatory conditions, and unresolved determinations.
Quick Start
Ask the connected AI agent to threat-model your application and provide its architecture, data flows, key assets, named dependencies with versions, AI features, and coarse legal posture in prose.