security-requirement-extraction

Convert STRIDE threats into structured security requirements with acceptance criteria.

Updated Apr 25, 2026
One-click install
npx skills add https://github.com/tomasbasso/SistemaStockV2 --skill security-requirement-extraction-tomasbasso
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-requirement-extraction
Source: https://github.com/tomasbasso/SistemaStockV2/tree/main/.agents/skills/analisis-requisitos-seguridad
Command: npx skills add https://github.com/tomasbasso/SistemaStockV2 --skill security-requirement-extraction-tomasbasso

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Derives security requirements from threat models and business context, ensuring threats are translated into testable controls, actionable user stories, and measurable acceptance criteria.

Core Features & Use Cases

  • Threat-to-requirement mapping: automatically convert STRIDE threats into structured SecurityRequirement objects.
  • Rationale, traceability, and testing: link requirements to threats and compliance needs, with acceptance criteria and test cases.
  • Output formats: generate user stories and test specifications suitable for risk assessments and security reviews.

Quick Start

Provide a set of threat inputs and business context to generate corresponding security requirements.

Frequently Asked Questions about security-requirement-extraction

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I convert threat models into testable security requirements?

Deriving security requirements from threat models involves mapping STRIDE threats and business context into structured objects. This generates testable controls with defined priority, rationale, and acceptance criteria for risk assessment and security test planning.

What is the best way to generate security user stories from a risk assessment?

Generating security user stories from risk assessment involves transforming identified threats and business context into structured requirements. The output produces traceable user stories equipped with measurable acceptance criteria and corresponding test cases.

How does threat-to-requirement mapping handle traceability and test cases?

Threat-to-requirement mapping ensures traceability by linking generated security requirements directly to original threats and compliance needs. It automatically outputs corresponding test cases and acceptance criteria to ensure threats become measurable, testable controls.

Can I use business context to prioritize security requirements during threat modeling?

Yes, business context directly drives the prioritization of security requirements during threat modeling. Providing business context alongside threat inputs generates structured requirements that include priority levels, rationale, and specific acceptance criteria.

What inputs do I need to generate security test specifications from threats?

Generating security test specifications from threats requires a set of threat inputs and relevant business context. These inputs are processed to output structured security requirements complete with test cases and acceptance criteria for security reviews.