security-engineer

Identify and remediate application security vulnerabilities across code, infrastructure, and dependencies.

Updated Mar 25, 2026
One-click install
npx skills add https://github.com/ouakar/ubinarys-dental --skill security-engineer-ouakar
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-engineer
Source: https://github.com/ouakar/ubinarys-dental/tree/main/skills/forgewright/skills/security-engineer
Command: npx skills add https://github.com/ouakar/ubinarys-dental --skill security-engineer-ouakar

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Security-engineer provides production-grade application security audits, threat modeling, and remediation planning across code, dependencies, and infrastructure.

Core Features & Use Cases

  • Comprehensive threat modeling (STRIDE) and OWASP Top 10 code audit guidance
  • End-to-end auth, data security, and supply chain reviews with actionable remediation plans
  • Per-service findings with traceability to exact files and lines

Quick Start

Run a full security assessment across the codebase to generate a prioritized remediation plan.

Frequently Asked Questions about security-engineer

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a security audit on my codebase using OWASP Top 10 guidelines?

Perform a production-grade security audit by applying OWASP Top 10 code review and STRIDE threat modeling across full-stack applications, microservices, and AI-enabled workflows to identify vulnerabilities. It delivers per-service findings with exact file and line traceability.

What is STRIDE threat modeling and how does it apply to microservices security?

STRIDE threat modeling is a framework for identifying security threats across code, infrastructure, and dependencies. It enforces this methodology during microservices security reviews to map vulnerabilities and generate comprehensive remediation plans.

Can I use this security audit workflow in my CI/CD pipelines?

Yes, you can use this security audit workflow in CI/CD pipelines. It is explicitly designed to identify and remediate application security vulnerabilities across code, infrastructure, and dependencies within production and CI/CD environments.

How do I generate a Software Bill of Materials (SBOM) and check supply chain dependencies?

Generate an SBOM and review supply chain security by auditing your application dependencies. The audit process includes end-to-end supply chain reviews and SBOM generation to identify vulnerable components and provide actionable remediation plans.

Does this security audit cover data protection and RBAC remediation planning?

Yes, the audit covers RBAC and data protection remediation planning. It enforces end-to-end auth and data security reviews across your codebase, providing a prioritized remediation plan across six comprehensive phases.

What is the best way to remediate security vulnerabilities found during a code review?

The best way to remediate security vulnerabilities is to follow a prioritized remediation plan generated after a full code review. It maps identified threats to actionable steps across six phases, ensuring comprehensive vulnerability resolution.