security-architect

Identify and implement OWASP Top 10 security controls for BC Gov .NET/React/OpenShift projects.

7|Updated Mar 5, 2026
One-click install
npx skills add https://github.com/rloisell/rl-agents-n-skills --skill security-architect-rloisell
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-architect
Source: https://github.com/rloisell/rl-agents-n-skills/tree/main/security-architect
Command: npx skills add https://github.com/rloisell/rl-agents-n-skills --skill security-architect-rloisell

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill provides security design guidance, threat modelling workflows, and hardening roadmaps for BC Government projects to reduce vulnerabilities across the software lifecycle.

Core Features & Use Cases

  • Threat modelling and security architecture reviews for .NET, React, and OpenShift deployments.
  • OWASP Top 10 mitigations and secure coding practices integrated into design reviews.
  • Secrets management and container security baselines, including Vault integration and OIDC session controls.
  • Use Case: When designing a new service, define security controls, map STRA/PIA requirements, and plan audit logging and compliance steps.

Quick Start

Describe the security architecture for a new BC Gov service and outline required STRA/PIA steps along with container hardening measures.

Frequently Asked Questions about security-architect

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I map OWASP Top 10 mitigations for a .NET and React application?

OWASP Top 10 mitigations are identified through security architecture reviews that integrate secure coding practices into design workflows, reducing vulnerabilities across the .NET and React application lifecycle.

What is the process for threat modelling BC Gov services deployed on OpenShift?

Threat modelling for BC Gov OpenShift deployments provides structured workflows to identify security risks, define architecture controls, and document container hardening roadmaps across the software lifecycle.

How do I implement secrets management with Vault and OIDC session controls?

Secrets management with Vault and OIDC session controls are implemented by establishing security baselines that configure Vault integration and manage OIDC sessions for BC Gov applications.

Can I use this security architecture review for existing services or only new builds?

Security architecture reviews scope both new and existing BC Gov services, mapping STRA/PIA requirements, audit logging, and compliance steps to guide secure development and operations.

What's the best way to document container security hardening steps for compliance?

Container security hardening steps are documented in AI/securityNextSteps.md, providing tooling recommendations, compliance steps, and hardening roadmaps to guide secure development and operations.

When do I need to perform STRA and PIA steps for BC Gov applications?

STRA and PIA steps are required when designing a new BC Gov service, mapping security controls and compliance requirements during the initial architecture review phase.