Security

Generate STRIDE threat models and map CMMC compliance baselines for PAI projects.

Updated Dec 2, 2025
One-click install
npx skills add https://github.com/banjoey/FORGE --skill security-banjoey
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: Security
Source: https://github.com/banjoey/FORGE/tree/main/.claude/skills/Security
Command: npx skills add https://github.com/banjoey/FORGE --skill security-banjoey

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Proactively identifies and maps security requirements and threat models for PAI projects, enabling secure-by-design decisions and CMMC alignment from the earliest stages.

Core Features & Use Cases

  • ThreatModel workflow integration: automatically generate STRIDE threats and mitigations for new features.
  • CMMC baseline mapping: map features to CMMC practices and create remediation roadmaps.
  • Cross-skill integration: integrates with AgilePm, TestArchitect, and Standup to embed security into user stories and testing.
  • Threat modeling artifacts: produces threat model documents (threat-model.md) and security guidance for architecture and implementation.
  • Documentation & governance: supports project-wide threat modeling discipline and traceability across architecture and development.

Quick Start

Threat-model a feature by loading Security → ThreatModel workflow to generate STRIDE threats and mitigations.

Frequently Asked Questions about Security

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate STRIDE threats and mitigations for new features?

To generate STRIDE threats and mitigations, load the ThreatModel workflow to automatically identify and map security requirements and threat models for your project features.

What is shift-left security and how does it apply to project design?

Shift-left security proactively identifies and maps security requirements during the earliest feature design stages, enabling secure-by-design decisions before implementation begins.

Can I integrate threat modeling artifacts with agile project management?

Yes, cross-skill integration embeds security into agile user stories and testing by producing threat model documents and security guidance for architecture.

How do I map CMMC compliance baselines to project features?

You map features to CMMC practices by applying threat modeling to create compliance baselines and generate remediation roadmaps for your project.

Does this security workflow support traceability across architecture and development?

Yes, the workflow supports project-wide threat modeling discipline and traceability across architecture and development by generating threat-model artifacts.