secure-arch

Audit system architecture for zero-trust gaps and defense-in-depth weaknesses.

3|Updated May 28, 2026
One-click install
npx skills add https://github.com/mahg-es/araya --skill secure-arch
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: secure-arch
Source: https://github.com/mahg-es/araya/tree/main/skills/secure-arch
Command: npx skills add https://github.com/mahg-es/araya --skill secure-arch

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Audit system architecture for security to identify zero-trust gaps and defense-in-depth weaknesses.

Core Features & Use Cases

  • Threat modeling guidance: provides structured review criteria for trust boundaries, data flows, and IAM models.
  • Architecture governance: evaluates network segmentation, secure defaults, and secure-by-design principles.
  • Use Case: pre-release security architecture review for new services or third-party integrations handling sensitive data.

Quick Start

Provide your architecture diagram and threat model to begin the zero-trust security review.

Frequently Asked Questions about secure-arch

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I audit system architecture for zero-trust security gaps?

Audit system architecture for zero-trust security by evaluating trust boundaries, data flows, IAM models, and network segmentation to identify defense-in-depth weaknesses. This enforces least privilege and secure defaults across cloud and on-prem environments.

What is threat modeling for trust boundaries and data flows?

Threat modeling for trust boundaries and data flows is a structured review criteria process to evaluate secure-by-design principles. It assesses IAM models and secure defaults to identify zero-trust gaps in new service integrations.

Can I use this architecture review for cloud and on-prem environments?

Yes, you can use this architecture review for cloud and on-prem environments. It evaluates data-handling systems, network segmentation, and auditing requirements across both deployment models to ensure zero-trust principles apply universally.

How do I review IAM models and network segmentation for secure defaults?

Review IAM models and network segmentation for secure defaults by applying architecture governance to your system design. This evaluates least privilege enforcement and secure-by-design principles during pre-release security architecture reviews.

What's the best way to prepare for a zero-trust security architecture review?

The best way to prepare for a zero-trust security architecture review is to provide your architecture diagram and threat model. This allows the evaluation of trust boundaries, data flows, and auditing requirements to identify defense-in-depth weaknesses.

When do I need a pre-release security architecture review for new services?

You need a pre-release security architecture review for new services when handling sensitive data or integrating third-party systems. It enforces zero-trust principles by evaluating IAM models, network segmentation, and secure defaults before deployment.