security-engineering

Identify and mitigate software security risks using STRIDE and OWASP Top 10.

116|9|Updated Feb 18, 2026
One-click install
npx skills add https://github.com/elophanto/EloPhanto --skill security-engineering-elophanto
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-engineering
Source: https://github.com/elophanto/EloPhanto/tree/main/skills/security-engineering
Command: npx skills add https://github.com/elophanto/EloPhanto --skill security-engineering-elophanto

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Application security is an ongoing risk that can derail projects, increase incident costs, and erode trust. This skill provides a structured approach to identify, prioritize, and remediate security risks early in the software lifecycle.

Core Features & Use Cases

  • Threat modeling sessions to map data flows, trust boundaries, and identify STRIDE-based risks.
  • Secure code reviews focusing on OWASP Top 10, CWE guidance, and secure coding practices.
  • Security architecture design and defense-in-depth planning across cloud, on-prem, and hybrid environments.

Quick Start

Initiate a threat-modeling session for your stack and begin secure code reviews using STRIDE and OWASP guidance.

Frequently Asked Questions about security-engineering

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I conduct threat modeling for my software architecture?

Threat modeling maps data flows and trust boundaries to identify STRIDE-based security risks. This skill guides sessions to map architecture, identify threats, and prioritize mitigations during design reviews and architecture refreshes.

What is the best way to integrate secure code reviews into my SDLC?

Secure code reviews integrated into the SDLC use OWASP Top 10 and CWE guidance to identify vulnerabilities. This skill provides structured code audits focusing on secure coding practices to mitigate application security risks early.

Can I use STRIDE analysis for mobile and cloud applications?

Yes, STRIDE analysis supports threat modeling across web, mobile, and cloud applications. The skill applies threat modeling and vulnerability assessment to identify security risks during design reviews for diverse deployment environments.

How do I align vulnerability assessments with OWASP Top 10?

Vulnerability assessments align with OWASP Top 10 by applying secure code reviews and CWE guidance. This skill identifies security risks and provides guided remediation with actionable steps to ensure compliance and secure design.

When do I need security architecture design for defense-in-depth planning?

Security architecture design is needed for defense-in-depth planning across cloud, on-prem, and hybrid environments. This skill supports architecture refreshes to establish secure design and mitigate vulnerabilities across your infrastructure.

Does this security engineering skill provide actionable remediation steps?

Yes, the security engineering skill provides guided remediation with actionable steps. It identifies and mitigates security risks through vulnerability assessments and secure code reviews, ensuring structured remediation during the software lifecycle.