What problem does it solve?
This Skill helps you proactively find security weaknesses by combining supply-chain checks, OWASP Top 10 code review, and STRIDE threat modeling into scored, structured audit outputs.
Core Features & Use Cases
- Supply chain risk scanning: dependency vulnerability auditing plus secrets detection, CI/CD workflow review, and LLM/prompt-injection risk checks with structured JSON output.
- OWASP Top 10 review: systematic category coverage using CCW CLI analysis augmented by targeted pattern scans.
- STRIDE threat modeling: maps threats to architecture components, identifies trust boundaries, and produces a consolidated threat model artifact.
- Trend-tracked reporting: aggregates findings into dated reports in .workflow/.security/ for regression monitoring and gate evaluation.
Quick Start
Run a comprehensive audit by asking the AI to execute the four phases sequentially and write the final scored report into .workflow/.security/.