What problem does it solve? Founders and operators often lack a structured way to decide which cyber risks to fix first, leading to scattered security spending and unaddressed critical exposures. This Skill turns asset inventories, threat models, and control gaps into an evidence-backed, prioritized security posture assessment and operating plan. ## Core Features & Use Cases - Risk Prioritization Framework: Inventory critical assets, map threats and attack paths, assess controls, and estimate likelihood and impact to rank remediation work. - Decision-Grade Outputs: Produces a diagnosis with evidence and confidence, ranked options with risk-adjusted value, a remediation plan with owners and approvals, and monitoring thresholds. - Governed Execution: Enforces autonomy ceilings, human approval requirements for material commitments, and escalation paths to legal, compliance, and security professionals. - Use Case: A founder asks which security investments to make this quarter within a fixed budget. The Skill loads company context, evaluates at least three feasible options against hard constraints, and recommends the highest confidence-weighted remediation portfolio with KPIs like critical exposure, control coverage, and remediation age. ## Quick Start Ask the agent to run a security posture assessment for your company, prioritizing remediation within your current budget and risk tolerance.