security-eng

Perform threat modeling and vulnerability assessment for web and cloud-native applications.

2|Updated Feb 25, 2026
One-click install
npx skills add https://github.com/elihuvillaraus/skills --skill security-eng
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-eng
Source: https://github.com/elihuvillaraus/skills/tree/main/security-eng
Command: npx skills add https://github.com/elihuvillaraus/skills --skill security-eng

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill addresses the critical need for robust application security by proactively identifying and mitigating vulnerabilities throughout the software development lifecycle.

Core Features & Use Cases

  • Threat Modeling: Systematically identify potential security threats and design weaknesses before development begins.
  • Vulnerability Assessment: Conduct thorough code reviews and security testing to uncover exploitable flaws.
  • Secure Architecture Design: Build secure-by-design systems with defense-in-depth and zero-trust principles.
  • Use Case: Integrate this Skill into your CI/CD pipeline to automatically scan code for common vulnerabilities and ensure secure configurations are applied to your cloud infrastructure.

Quick Start

Use the security-eng skill to perform a threat model analysis on the provided system architecture diagram.

Frequently Asked Questions about security-eng

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform threat modeling for cloud-native applications?

Threat modeling for cloud-native applications systematically identifies potential security threats and design weaknesses before development begins. It constructs secure-by-design systems applying defense-in-depth and zero-trust principles to mitigate risks early.

What is secure code review and how does it find exploitable vulnerabilities?

Secure code review is a vulnerability assessment process conducting thorough code analysis and security testing to uncover exploitable flaws. It ensures robust application security by proactively identifying and mitigating vulnerabilities throughout the software development lifecycle.

Can I use vulnerability assessment to scan code automatically in a CI/CD pipeline?

Yes, you can integrate vulnerability assessment into your CI/CD pipeline to automatically scan code for common vulnerabilities. This ensures secure configurations are continuously applied to your cloud infrastructure during deployments.

What's the best way to design secure architecture with defense-in-depth?

Secure architecture design with defense-in-depth builds secure-by-design systems using zero-trust principles. It establishes multiple layers of security controls to protect modern web and cloud-native applications against potential threats.

Does this vulnerability assessment provide actionable remediation steps for identified risks?

Yes, the vulnerability assessment requires actionable remediation steps for all identified risks. It delivers expert application security engineering by ensuring every uncovered exploitable flaw has a concrete mitigation strategy.