security-expert

Identify and analyze software threats using STRIDE, PASTA, and attack trees.

1|Updated Apr 13, 2026
One-click install
npx skills add https://github.com/felixgeelhaar/skills --skill security-expert-felixgeelhaar
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-expert
Source: https://github.com/felixgeelhaar/skills/tree/main/security-expert
Command: npx skills add https://github.com/felixgeelhaar/skills --skill security-expert-felixgeelhaar

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Senior security thinking partner to help teams threat-model, assess risks, and guide secure development across architectures and processes.

Core Features & Use Cases

  • Threat modeling with STRIDE, PASTA, and attack trees across system components.
  • Comprehensive guidance on application security frameworks (OWASP Top 10 2025, ASVS 5.0), Zero Trust, supply chain security (SLSA, SBOM), and regulatory compliance (SOC 2, GDPR, HIPAA, PCI-DSS, ISO 27001).
  • Incident response planning, secure development lifecycle reviews, and pairing with adjacent experts when needed.

Quick Start

Provide your system design and I will perform a threat-modeling exercise using STRIDE, PASTA, and attack trees to identify risks and propose mitigations.

Frequently Asked Questions about security-expert

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform STRIDE threat modeling for a cloud architecture?

PASTA threat modeling analyzes risks across system components by mapping attack trees and data flows, uncovering attack surfaces to produce structured risk statements and prioritized mitigations aligned with secure development goals.

Can I use threat modeling to check compliance with SOC 2 and GDPR requirements?

Threat modeling supports compliance with SOC 2, GDPR, HIPAA, PCI-DSS, and ISO 27001 by evaluating system designs to identify risks and produce residual risk guidance aligned with regulatory and secure development requirements.

What's the best way to assess zero-trust security and supply chain risks?

Assessing zero-trust security and supply chain risks involves applying SLSA and SBOM frameworks to analyze architectures, uncover attack surfaces, and generate prioritized mitigations for secure development lifecycle reviews.

Does OWASP ASVS 5.0 work with attack tree analysis for application security?

OWASP ASVS 5.0 integrates with attack tree analysis by evaluating application security frameworks against identified threats, producing structured risk statements and mitigation guidance for secure development workflows.

When do I need formal threat modeling frameworks instead of informal risk reviews?

Formal threat modeling frameworks like STRIDE and PASTA are needed when uncovering attack surfaces across complex architectures, data flows, and supply chains requires structured risk statements and prioritized mitigations for compliance alignment.