security-requirement-extraction

Extract security requirements from threat models and business context.

3|1|Updated Feb 3, 2026
One-click install
npx skills add https://github.com/duanbiao2000/obsidianDoc26 --skill security-requirement-extraction-duanbiao2000
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-requirement-extraction
Source: https://github.com/duanbiao2000/obsidianDoc26/tree/main/agents-main/plugins/security-scanning/skills/security-requirement-extraction
Command: npx skills add https://github.com/duanbiao2000/obsidianDoc26 --skill security-requirement-extraction-duanbiao2000

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Transforms threat models and business context into concrete security requirements that guide secure design, development, and verification, enabling traceability from threats to controls and tests.

Core Features & Use Cases

  • Convert threats into actionable security requirements linked to risks and compliance.
  • Generate security user stories, acceptance criteria, and test specifications for development and QA.
  • Produce a structured requirements set and traceability artifacts for audits and compliance reviews.

Quick Start

Provide a threat model and project context, and have me derive security requirements, user stories, and test cases.

Frequently Asked Questions about security-requirement-extraction

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I extract security requirements from a threat model?

To extract security requirements from a threat model, you provide the threat model and project context to derive concrete security requirements, user stories, and test cases. This ensures traceability from identified threats to specific controls.

What is the best way to generate security user stories from threat modeling?

Generating security user stories from threat modeling involves translating identified threats into actionable requirements and acceptance criteria. This process creates test specifications for development and QA while maintaining risk awareness and compliance evidence.

How do I create security test cases based on business context and threats?

Creating security test cases based on business context and threats requires applying threat models to build structured requirements. This translates threats into testable security user stories and acceptance criteria for verification.

Can I build compliance evidence and traceability artifacts from security requirements?

Yes, you can build compliance evidence and traceability artifacts from security requirements. Extracting threats into structured requirements produces traceability artifacts that map controls directly to risks for audits and compliance reviews.

Does translating threats into requirements support priority assignment and risk management?

Translating threats into requirements directly supports priority assignment and risk management. The extraction process ensures risk awareness and priority assignment are applied throughout the workflow to guide secure design and verification.

When do I need to translate threats into security requirements?

You need to translate threats into security requirements when transforming threat models and business context into concrete controls. This is required to guide secure design, development, and verification while ensuring traceability from threats to tests.