security-analyst

Classify security findings with OWASP, CWE, and CVSS v3.1 scoring.

50|9|Updated Oct 15, 2025
One-click install
npx skills add https://github.com/jpoley/flowspec --skill security-analyst
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-analyst
Source: https://github.com/jpoley/flowspec/tree/main/.claude/skills/security-analyst
Command: npx skills add https://github.com/jpoley/flowspec --skill security-analyst

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill empowers security teams to quickly classify vulnerabilities, quantify risk, and map findings to compliance frameworks using standardized references such as OWASP, CWE, and CVSS. It provides a structured approach to triage, prioritization, and reporting, reducing time to remediation.

Core Features & Use Cases

  • Vulnerability Classification: OWASP Top 10 mapping, CWE taxonomy, CVSS v3.1 scoring with justification.
  • Risk Quantification: Business impact analysis and prioritization guided by CVSS and asset criticality.
  • Compliance Mapping: Align findings to SOC 2, ISO 27001, PCI-DSS, HIPAA controls.
  • Use Case: A security team triages hundreds of findings and generates remediation plans and executive summaries.

Quick Start

Use the security-analyst skill to analyze a vulnerability finding and generate a prioritized remediation plan.

Frequently Asked Questions about security-analyst

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I classify vulnerabilities using OWASP Top 10 and CVSS scoring?

OWASP Top 10 classification maps vulnerabilities to known attack categories, while CVSS v3.1 scoring quantifies severity on a 0–10 scale with justified metrics. This Skill automates both mappings and generates scores with business impact analysis to prioritize remediation across your findings.

Can I map security findings to SOC 2, ISO 27001, and PCI-DSS compliance frameworks?

Yes. This Skill aligns classified vulnerabilities to SOC 2, ISO 27001, PCI-DSS, and HIPAA controls, enabling compliance teams to track remediation against specific regulatory requirements and audit readiness.

What's the best way to triage and prioritize hundreds of security findings?

Use CWE taxonomy categorization and CVSS-driven risk quantification to rank findings by business impact and asset criticality. This Skill generates prioritized remediation plans and executive summaries for rapid triage at scale.

How does CWE taxonomy help with vulnerability assessment and remediation planning?

CWE (Common Weakness Enumeration) organizes root causes of vulnerabilities into a structured taxonomy. This Skill maps findings to CWE categories to standardize remediation guidance and reduce duplicate efforts across your security team.

Do I need existing vulnerability data or specific input formats to use this Skill?

Provide a security finding with details like description, affected component, and severity indicators. The Skill accepts structured vulnerability reports and outputs OWASP, CWE, and CVSS classifications with compliance mappings and remediation steps.

What compliance frameworks does this Skill support for risk assessment?

This Skill covers SOC 2, ISO 27001, PCI-DSS, and HIPAA compliance contexts. It maps risk assessments and CVSS scores to controls within each framework for audit documentation and remediation tracking.