What problem does it solve?
This Skill helps security reviewers and architects detect missing security considerations in planning documents before implementation, focusing on attack surface, auth/authz assumptions, data exposure, third-party trust boundaries, and secrets management so risks are addressed earlier in the lifecycle.
Core Features & Use Cases
- Attack surface inventory: Identify new endpoints, data stores, integrations, and user inputs that lack documented access controls or validation and produce a finding for each gap.
- Auth/authz gaps: Flag functionality described without actor or permission decisions and highlight new roles or privilege changes that need boundaries.
- Data exposure & secrets: Assess identification of sensitive data, protections for transit/rest/logs, retention, and credential management practices.
- Third-party trust & threat modeling: Surface undocumented trust assumptions, failure modes, and produce the top three likely plan-level exploits with one-sentence mitigations.
- Use Cases: Pre-release architecture reviews, design PR reviews, compliance checkpoints, and product planning validations.
Quick Start
Review this plan and produce per-element security findings, confidence levels, and a concise top-three plan-level threat model with one-sentence mitigations.