security-requirement-extraction

Converts threat models and business context into actionable security requirements and test plans.

1|Updated Apr 27, 2026
One-click install
npx skills add https://github.com/haxlys/skills --skill security-requirement-extraction-haxlys
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-requirement-extraction
Source: https://github.com/haxlys/skills/tree/main/vendored/wshobson-agents/plugins/security-scanning/skills/security-requirement-extraction
Command: npx skills add https://github.com/haxlys/skills --skill security-requirement-extraction-haxlys

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Automatically translate threat models and business context into concrete, testable security requirements that guide design, implementation, and verification.

Core Features & Use Cases

  • Threat-to-requirement mapping: converts identified threats into structured requirements across functional, non-functional, and compliance domains.
  • Automated documentation: generates user stories, acceptance criteria, and test cases from threats for faster governance.
  • Compliance alignment: links requirements to common frameworks to support audits and policy adherence.

Quick Start

Provide a structured threat input set and a project name to generate a complete security requirements set.

Frequently Asked Questions about security-requirement-extraction

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I convert threat models into security requirements?

You generate security requirements from threat models by providing a structured threat input set and project name, which yields functional, non-functional, and compliance controls mapped directly to your identified threats.

How does threat-to-requirement mapping work for security user stories?

Threat-to-requirement mapping translates identified threats into structured security user stories, automatically generating actionable acceptance criteria and test cases to guide secure implementation and faster governance.

Can I generate security test cases from a risk assessment?

Yes, you can generate security test cases from a risk assessment by mapping identified threats to testable acceptance criteria, yielding complete test plans that guide verification across projects of varying risk.

Does this approach align security requirements with compliance frameworks?

Yes, this approach aligns security requirements with compliance frameworks by linking derived threats to common compliance domains, supporting audits and ensuring policy adherence through automated documentation.

What is the best way to automate security documentation from threat modeling?

The best way to automate security documentation from threat modeling is to derive security requirements from business context, automatically generating user stories, acceptance criteria, and test plans for faster governance.