security-review

Execute a 7-step security review of code and architecture.

3|Updated Mar 1, 2026
One-click install
npx skills add https://github.com/onblueroses/strata --skill security-review-onblueroses
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-review
Source: https://github.com/onblueroses/strata/tree/main/skills/security-review
Command: npx skills add https://github.com/onblueroses/strata --skill security-review-onblueroses

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This Skill provides a comprehensive and systematic security review of code and architecture, identifying and mitigating potential vulnerabilities.

Core Features & Use Cases

  • 7-Step Workflow: Automates a 7-step security review process, including threat modeling, code review, and pen testing.
  • Security+ Knowledge: Integrates Security+ certified knowledge to cover essential security areas.
  • Auto-Trigger: Automatically initiates review when security-related actions are performed or specific code types are written.

Quick Start

Run the 'security-review' skill to initiate a comprehensive security review of your codebase.

Frequently Asked Questions about security-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate a security review and vulnerability assessment for my codebase?

Automate a security review by running a predefined 7-step process that executes threat modeling, code analysis, and penetration testing. This workflow systematically identifies and mitigates known vulnerabilities in your architecture.

What is threat modeling and how does it fit into a code security workflow?

Threat modeling is a structured process to identify potential security threats. It serves as an initial phase in a comprehensive security workflow, ensuring your code and architecture are assessed for vulnerabilities before mitigation.

Can I use this security workflow for penetration testing and known vulnerability mitigation?

Yes, the security workflow includes automated penetration testing alongside code review and threat modeling. It integrates Security+ knowledge to enforce robust security and mitigate known vulnerabilities effectively.

Does automated code analysis require Security+ knowledge to identify vulnerabilities?

No, the automated code analysis integrates Security+ certified knowledge internally. It automatically covers essential security areas when specific code types are written or security-related actions are performed.

When do I need to initiate a comprehensive security review for my software project?

You need a comprehensive security review when your project requires robust security enforcement. The review auto-triggers when specific code types are written or security-related actions are performed during development.