What problem does it solve? Translating threat analysis into concrete, testable security requirements is often ad hoc and inconsistent, leaving gaps between identified threats and implemented controls. This Skill provides structured templates to derive requirements from STRIDE threats, map them to compliance frameworks, and generate user stories and test cases. ## Core Features & Use Cases - Threat-to-Requirement Extraction: Convert STRIDE-categorized threats into prioritized security requirements with acceptance criteria and test cases. - Compliance Mapping: Map requirements to PCI DSS, HIPAA, GDPR, and OWASP controls, and run gap analysis to find missing coverage. - Security User Stories: Generate agile-ready user stories and epics with definition-of-done checklists and traceability to threats. - Use Case: After completing a threat model for a payment API, feed the identified threats into the extractor to produce a prioritized requirement set with a threat-to-requirement traceability matrix and compliance gap report. ## Quick Start Analyze my threat model for the checkout service and generate prioritized security requirements with acceptance criteria and OWASP compliance mapping.