security-privacy

Model security threats and privacy risks across the data lifecycle.

Updated Jul 20, 2026
One-click install
npx skills add https://github.com/loveconnor/clove-skills --skill security-privacy-loveconnor
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-privacy
Source: https://github.com/loveconnor/clove-skills/tree/main/.agents/skills/security-privacy
Command: npx skills add https://github.com/loveconnor/clove-skills --skill security-privacy-loveconnor

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This skill addresses the complexity of building secure and privacy-compliant software by providing a structured framework for threat modeling, risk assessment, and evidence-based control implementation.

Core Features & Use Cases

  • Threat & Privacy Modeling: Systematically identify vulnerabilities, abuse cases, and privacy risks across the entire data lifecycle.
  • Control Specification: Define testable preventive, detective, and recovery controls based on authoritative standards like NIST and OWASP.
  • Incident Readiness: Plan for breach communication, recovery, and post-incident learning with clear operational guidelines.

Quick Start

Use the security-privacy skill to perform a threat model on the current system architecture and identify necessary controls.

Frequently Asked Questions about security-privacy

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a threat model on my software architecture?

Threat modeling systematically identifies vulnerabilities and abuse cases across the data lifecycle to define testable preventive, detective, and recovery controls based on standards like NIST and OWASP.

What is the best way to design privacy controls for the data lifecycle?

Designing privacy controls involves modeling privacy risks across the entire data lifecycle and specifying evidence-based controls to satisfy regulatory compliance and supply-chain risk management requirements.

How do I plan for incident recovery and breach communication?

Incident recovery planning establishes operational guidelines for breach communication, system recovery, and post-incident learning to ensure structured readiness and regulatory compliance after a security event.

Can I use this to audit authentication and authorization workflows?

Auditing authentication and authorization workflows applies threat modeling and risk assessment to verify robust access controls and generate evidence-based security compliance documentation.

Does this approach support NIST and OWASP compliance requirements?

NIST and OWASP compliance is supported through the specification of testable preventive, detective, and recovery controls mapped to authoritative standards for evidence-based security audits.

What are the limitations of threat modeling for supply-chain risk management?

Threat modeling for supply-chain risk management focuses on identifying vulnerabilities and specifying controls, but requires continuous evidence-based auditing to maintain regulatory compliance and detect emerging threats.