security

Analyze security findings and incidents to produce actionable remediation plans.

Updated Aug 23, 2026
One-click install
npx skills add https://github.com/kittne/codex-skills-by-codex --skill security-kittne
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security
Source: https://github.com/kittne/codex-skills-by-codex/tree/main/security
Command: npx skills add https://github.com/kittne/codex-skills-by-codex --skill security-kittne

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Security teams need structured, evidence-backed analysis of findings and incidents to produce actionable remediation plans that reduce risk and ensure verifiability.

Core Features & Use Cases

  • Evidence-driven vulnerability analysis, incident triage, and threat modeling to identify root causes and control gaps.
  • Actionable remediation plans with verification steps, guardrails, and clear ownership to accelerate remediation.
  • Use Case: When a security finding is reported, generate scope, collect evidence, assess risk, propose fixes, and define tests to validate effectiveness across software, cloud, and infra.

Quick Start

Provide an evidence-based security assessment and remediation plan for a given system.

Frequently Asked Questions about security

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I create an evidence-based remediation plan for a security finding?

To create an evidence-based remediation plan, you must collect explicit evidence, perform root-cause analysis, assess the risk rating, propose fixes, and define verification tests to validate effectiveness across your software, cloud, or infrastructure environments.

What is threat modeling and how does it identify control gaps?

Threat modeling is an evidence-driven analysis process used during incident triage to identify root causes and control gaps. It structures security analysis to map vulnerabilities and threats within software, cloud, and infrastructure environments.

Can I use this security analysis for cloud and infrastructure environments?

Yes, this security analysis applies to software, cloud, and infrastructure environments. It generates scope, collects evidence, assesses risk, and defines tests to validate remediation effectiveness across these diverse platforms.

How do I verify that a security fix is effective after remediation?

You verify a security fix is effective by defining and executing specific verification tests outlined in the remediation plan. These steps validate that the applied guardrails and fixes successfully reduce the assessed risk.

What's the best way to triage a security incident using root-cause analysis?

The best way to triage a security incident is through evidence-driven analysis that identifies root causes and control gaps. This approach assesses risk ratings and produces actionable remediation plans with clear ownership and guardrails.

Does secure-by-default design require explicit evidence collection?

Yes, secure-by-default design requires explicit evidence collection to support root-cause analysis and risk rating. This evidence ensures that proposed remediation templates and guardrails are actionable and verifiable.