What problem does it solve?
This Skill eliminates gaps in security review processes where assessments are either too theoretical to catch realistic exploitable risks, or too ad-hoc to provide actionable, validated remediation steps for applications, cloud infrastructure, and CI/CD systems.
Core Features & Use Cases
- Threat Modeling: Map assets, trust boundaries, actors, and abuse cases to identify realistic attack paths and prioritized mitigations.
- Vulnerability Triage: Prioritize CVEs and scanner findings by actual reachability and exploitability rather than generic CVSS scores.
- Secure Review: Audit authentication, authorization, secrets handling, cloud/CI exposure, and web application security controls with clear validation steps for each fix.
- Use Case: For example, use this Skill to review a new invoice download endpoint for IDOR risks, or validate that a CI/CD pipeline does not leak production secrets to forked pull requests.
Quick Start
Use the security-engineer skill to review the latest pull request for realistic exploitable security risks and provide prioritized remediation steps with validation tests.