security-review

Apply STRIDE threat modeling and compliance checks across development phases.

14|2|Updated Nov 7, 2025
One-click install
npx skills add https://github.com/kennedym-ds/copilot_orchestrator --skill security-review-kennedym-ds
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-review
Source: https://github.com/kennedym-ds/copilot_orchestrator/tree/main/.github/skills/security-review
Command: npx skills add https://github.com/kennedym-ds/copilot_orchestrator --skill security-review-kennedym-ds

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill provides a structured approach to security analysis, enabling teams to systematically identify threats, assess risks, and verify compliance across development lifecycles.

Core Features & Use Cases

  • STRIDE threat modeling patterns for authentication, authorization, data handling, and deployment security.
  • Risk rating framework with severity levels and remediation guidance aligned with SOC 2, GDPR, and HIPAA.
  • Secure coding templates, vulnerability patterns, and code review checklists for end-to-end security validation.
  • Multi-phase guidance covering planning, implementation, review, and completion to ensure governance and traceability.

Quick Start

Run a STRIDE-based threat model and compliance review for a new feature with an accompanying risk assessment template.

Frequently Asked Questions about security-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is STRIDE threat modeling and how does it apply to code review?

STRIDE threat modeling categorizes security risks like spoofing, tampering, and information disclosure. This skill applies STRIDE patterns across code, architecture, and configurations to identify vulnerabilities and produce structured threat models during the review phase.

How do I run a security risk assessment for SOC 2 and GDPR compliance?

Security risk assessment for SOC 2 and GDPR involves identifying threats and scoring risks. This skill provides a risk rating framework with severity levels and remediation guidance aligned to SOC 2, GDPR, and HIPAA controls to drive mitigations.

How do I integrate secure coding patterns into the software development lifecycle?

Integrate secure coding patterns by applying vulnerability assessments and checklists across planning, implementation, review, and completion phases. This skill generates secure coding templates and review checklists to ensure end-to-end security validation and traceability.

Can I use this threat modeling approach for existing architecture and deployment configurations?

Yes, threat modeling can be applied to existing architecture and deployment configurations. The skill analyzes authentication, authorization, data handling, and deployment security patterns to identify vulnerabilities and verify compliance across your current setup.

What's the best way to structure a vulnerability assessment for a new feature?

The best way to structure a vulnerability assessment is to run a STRIDE-based threat model early in planning. This skill produces structured guidance including threat models, risk scoring, and vulnerability patterns to guide secure implementation and audits.

Does this security review process require any specific dependencies or external tools?

No specific dependencies or external tools are required. The skill provides self-contained security analysis patterns, risk frameworks, and compliance checklists to guide threat modeling and vulnerability assessment directly within your workflow.