What problem does it solve? Designing and reviewing security for applications and infrastructure is complex, and teams often either skip it or over-engineer controls that don't match their actual risk. This Skill provides structured, stage-appropriate security guidance so you can threat-model, review, and harden systems without guesswork. ## Core Features & Use Cases - Threat Modeling: Run a 5-minute threat model or a full STRIDE analysis with ready-made templates and risk tables. - Auth Design: Follow decision trees and checklists for authentication (sessions vs JWT, MFA, password policies) and authorization (RBAC, ABAC, ReBAC). - Security Reviews & Incident Response: Apply OWASP Top 10 checklists, HTTP security header configs, adversarial review prompts, and a 6-step incident response template. - Use Case: Before launching a new payments feature, ask for a security review to get an OWASP-based checklist covering access control, injection, cryptographic failures, and a verdict on whether the feature passes. ## Quick Start Ask the AI to perform a security review of your authentication flow using the OWASP checklist and threat modeling templates.