security-review

Identify security risks and validate HIPAA and GDPR compliance for PHI and PII solutions.

Updated Jan 26, 2026
One-click install
npx skills add https://github.com/thehivegroup-ai/ai-development --skill security-review-thehivegroup-ai
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-review
Source: https://github.com/thehivegroup-ai/ai-development/tree/main/modules/enterprise-standards/skills/security-review
Command: npx skills add https://github.com/thehivegroup-ai/ai-development --skill security-review-thehivegroup-ai

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This Skill systematically analyzes solutions handling regulated or sensitive data, identifying threats, mapping data flows, and validating compliance with security standards.

Core Features & Use Cases

  • Security Analysis: In-depth analysis of security threats, including threat modeling, vulnerability assessment, and compliance checks.
  • Data Classification: Classify and categorize data handled by the solution based on sensitivity.
  • Compliance Validation: Validates solution against security standards like OWASP Top 10 and regulatory frameworks like HIPAA and GDPR.
  • Use Case: For a feature processing PHI data, this Skill will identify potential security risks, map data flows, and ensure compliance with HIPAA before deployment.

Quick Start

Run a security review for the "new_ehr_feature".

Frequently Asked Questions about security-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I ensure HIPAA and GDPR compliance for a feature processing sensitive PHI and PII data?

To ensure HIPAA and GDPR compliance for features processing PHI and PII, you need automated data classification, threat modeling, data flow mapping, and validation against OWASP Top 10 checklists to identify security risks before deployment.

What is the best way to map data flows and identify security threats in a regulated data solution?

The best way to map data flows and identify security threats is by applying the STRIDE threat modeling framework alongside automated data classification to systematically pinpoint vulnerabilities and ensure compliance with regulatory standards.

How does threat modeling using the STRIDE framework work for security analysis?

Threat modeling using the STRIDE framework works by systematically categorizing security threats across your solution's data flows, enabling targeted vulnerability assessments and validating compliance against OWASP Top 10 guidelines and HIPAA or GDPR regulations.

Do I need prior knowledge of the STRIDE framework and OWASP guidelines to run a security review?

Yes, you need prior knowledge of the STRIDE framework and OWASP guidelines to effectively run a security review, as the analysis relies on these methodologies to accurately model threats and validate compliance for sensitive data solutions.

Can I validate a new healthcare feature against HIPAA compliance checklists before deployment?

Yes, you can validate a new healthcare feature against HIPAA compliance checklists before deployment by automating data classification of PHI, mapping data flows, and running threat modeling to identify and mitigate potential security risks.

What security analysis limitations should I anticipate when reviewing complex data processing features?

When reviewing complex data processing features, anticipate that security analysis is constrained to identifying risks via STRIDE, OWASP Top 10, and GDPR or HIPAA checklists, requiring accurate data flow inputs to effectively map threats and classify sensitive data.