Security

Route security assessments across recon, web testing, and prompt-injection scenarios.

1|Updated Apr 16, 2026
One-click install
npx skills add https://github.com/davdunc/pai-framework --skill security-davdunc
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: Security
Source: https://github.com/davdunc/pai-framework/tree/main/skills/Security
Command: npx skills add https://github.com/davdunc/pai-framework --skill security-davdunc

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Security intelligence and assessment workflows that turn an identified target into an actionable picture of its attack surface, web weaknesses, and prompt/LLM risks.

Core Features & Use Cases

  • Unified security assessment & intelligence: Routes requests into recon, web app security testing, prompt-injection testing, security news scanning, and annual report analysis based on your intent.
  • Attack-surface driven outputs: Produces guidance and artifacts needed to prioritize testing across recon findings, web endpoints, injection vectors, and threat landscape signals.
  • Use case: When you need to assess an AI-enabled web app, this skill helps you map where attacks land (inputs/endpoints), test prompt-injection and guardrail bypass paths, and contextualize findings using current security news and annual threat reports.

Quick Start

Activate Security by asking for recon, web assessment, prompt-injection testing, security updates, or annual report analysis for an authorized target domain, IP, or application.

Frequently Asked Questions about Security

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform threat modeling and security assessment for a web application?

To perform security assessment, you route reconnaissance to map attack surfaces, execute web app testing on endpoints, and analyze threat landscape signals to prioritize real-world security risks across the target application.

What is prompt injection testing and how does it work for LLM applications?

Prompt injection testing assesses AI-enabled web apps by mapping where attacks land at inputs and endpoints, then actively testing prompt-injection vectors and guardrail bypass paths to identify LLM security weaknesses.

Can I use network reconnaissance to map the attack surface of an authorized target?

Yes, network reconnaissance maps the attack surface of an authorized target domain or IP by routing discovery requests to identify active endpoints, producing actionable intelligence for prioritizing subsequent security testing.

How do I aggregate security intelligence and analyze annual threat reports?

Security intelligence aggregation scans current security news and analyzes annual threat reports to contextualize application findings, providing a threat landscape picture that prioritizes testing across recon and injection vectors.

Does this security assessment workflow require specific dependencies or environments?

No external dependencies are required to execute the security assessment workflow, which routes intent-based requests for recon, web testing, and prompt-injection analysis directly against authorized target domains or applications.