security-review

Identify security gaps and produce a structured security review deliverable.

2|Updated Mar 15, 2026
One-click install
npx skills add https://github.com/Modular-Earth-LLC/solutions-architecture-agent --skill security-review-modular-earth-llc
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-review
Source: https://github.com/Modular-Earth-LLC/solutions-architecture-agent/tree/main/skills/security-review
Command: npx skills add https://github.com/Modular-Earth-LLC/solutions-architecture-agent --skill security-review-modular-earth-llc

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill helps organizations assess and document security posture for complex solutions, ensuring regulatory alignment and auditable artifacts.

Core Features & Use Cases

  • STRIDE threat modeling across the architecture and data flows
  • Compliance mapping for HIPAA, SOC 2, CCPA, GLBA, PCI-DSS
  • Defense-in-depth architecture guidance and guardrails
  • AI-specific security controls and governance considerations
  • Output-ready artifacts for risk reviews and audits

Quick Start

Initiate a STANDARD-depth security review for the current architecture and generate the security deliverables.

Frequently Asked Questions about security-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a STRIDE threat model for my application architecture?

To perform a STRIDE threat model, apply the methodology across your architecture and data flows to identify security gaps, spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege risks.

Can I use this security review to map compliance for HIPAA, SOC 2, and PCI-DSS?

Yes, you can use this security review to map compliance for HIPAA, SOC 2, CCPA, GLBA, and PCI-DSS. It validates your security posture against these non-functional requirements and generates output-ready compliance artifacts.

What is the best way to document defense-in-depth guardrails for an auditable risk review?

Documenting defense-in-depth guardrails involves generating structured artifacts like threat models and compliance mappings. This approach outlines remediation steps with risk-based priorities to produce auditable deliverables.

Does this security assessment include AI-specific controls and governance considerations?

Yes, this security assessment includes AI-specific security controls and governance considerations. It scopes the evaluation to your project's architecture to identify risks and validate the security posture of AI components.

How do I generate structured remediation steps with risk-based priorities after a security audit?

To generate structured remediation steps after a security audit, validate the security posture against non-functional requirements. This process outlines risk-based priorities and produces artifacts like threat models and guardrails.

When do I need threat modeling and compliance mapping for my system architecture?

You need threat modeling and compliance mapping when assessing complex solutions for regulatory alignment. It helps identify security gaps, ensures auditable artifacts are produced, and validates the architecture's defense-in-depth posture.