security-pro

Identify cross-platform security risks via threat modeling and defense-in-depth guidance.

1|Updated Jul 3, 2026
One-click install
npx skills add https://github.com/truongnat/skills --skill security-pro
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-pro
Source: https://github.com/truongnat/skills/tree/main/skills/security-pro
Command: npx skills add https://github.com/truongnat/skills --skill security-pro

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Security guidance that helps teams perform threat modeling, secure design, and defense-in-depth planning across web, mobile, API, and backend stacks.

Core Features & Use Cases

  • Threat modeling across full stack to identify risks and map them to effective controls.
  • Guidance for secure design, authn/authz, secrets management, API and client hardening, and operational security signals, with clear handoffs to stack-specific skills.
  • Supports authorized self-assessment and risk reporting, referencing MITRE ATT&CK, OWASP practices, and OSI/TCP-IP concepts for context.

Quick Start

Perform a security review across a web/mobile/API stack by applying threat-modeling and defense-in-depth principles.

Frequently Asked Questions about security-pro

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform threat modeling across web, mobile, API, and backend architectures?

Threat modeling across web, mobile, API, and backend architectures involves identifying risks and mapping them to actionable controls. This Skill guides you through secure design and defense-in-depth planning using policy references.

What is defense-in-depth planning and how does it apply to cross-platform security?

Defense-in-depth planning for cross-platform security layers actionable controls across web, mobile, API, and backend stacks. It enforces server-side validation and references OSI/TCP-IP concepts to mitigate identified threats.

Can I use this for secure design and authorization guidance in my application?

Yes, you can use this for secure design and authorization guidance. It provides authn/authz support, secrets management, API hardening, and operational security signals with clear handoffs to stack-specific skills.

How do I map identified application security risks to effective controls?

To map application security risks to effective controls, the Skill references MITRE ATT&CK and OWASP practices. It identifies threats and delegates implementation to sibling skills like nextjs-pro or postgresql-pro.

Does this provide implementation details for Node.js or Next.js backend hardening?

No, it delegates backend hardening to sibling skills like nestjs-pro and nextjs-pro. It focuses on secure design, threat modeling, and enforcing server-side controls rather than writing implementation code.

When do I need a cross-platform security review for my full stack application?

You need a cross-platform security review when identifying risks across web, mobile, API, and backend layers. It supports authorized self-assessment, risk reporting, and establishes defense-in-depth guidance before deployment.