What problem does it solve?
Perform design-time security analyses of specs, plans, or arbitrary project files, surfacing actionable findings to guide secure design decisions and reduce risk early in the SDLC.
Core Features & Use Cases
- Hybrid expert review paired with a STRIDE completeness sweep; LINDDUN is applied when data classification flags PII, credentials, or session data.
- Spec-scoped mode produces a security.md artifact alongside other spec artifacts; ad-hoc mode delivers findings in conversation with optional file output.
- Integrates with /jim:plan and /jim:build phase gates to validate security considerations during planning and execution.
Quick Start
Run /jim:sec on a target directory containing spec.md to initiate a design-time security review.