What problem does it solve?
Security reviews often happen too late or get skipped, leading to preventable vulnerabilities escaping into production; Security Architect turns threat modeling, secure code review, and auditing into a guided, on-demand workflow throughout the full build lifecycle.
Core Features & Use Cases
- DESIGN (Threat Modeling): Produces STRIDE/DREAD threat models and translates them into concrete security requirements before implementation.
- REVIEW (Code Security Check): Runs OWASP Top 10:2025 checks, secure code pattern validation, secrets scanning, and security-header review with risk-based severity and blocker rules.
- AUDIT (Full Security Scan): Evaluates the whole project including dependencies, configuration hardening, attack-surface mapping, and agentic AI security considerations.
- SKILL-SCAN (Prompt Injection Check for Skills): Scans external skill SKILL.md files for prompt-injection and unsafe behaviors (e.g., exfiltration, hijacking, destructive actions, settings manipulation) before installation.
Use cases include planning a new feature with a threat model, reviewing diffs before committing code, auditing a release candidate, and safely installing third-party skills with prompt-injection safeguards.
Quick Start
Tell the AI to run a security review by saying: "security review this code change".