security-self-assessment

Guide CNCF projects through creating and submitting TAG Security self-assessment questionnaires.

2|Updated Mar 4, 2026
One-click install
npx skills add https://github.com/castrojo/cncf-skills --skill security-self-assessment
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-self-assessment
Source: https://github.com/castrojo/cncf-skills/tree/main/skills/security-self-assessment
Command: npx skills add https://github.com/castrojo/cncf-skills --skill security-self-assessment

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill guides projects through creating a comprehensive self-assessment document detailing their security posture, threat model, and practices, which is crucial for CNCF graduation and reviews.

Core Features & Use Cases

  • Structured Documentation: Provides a step-by-step process to complete the official TAG Security self-assessment questionnaire.
  • Threat Modeling: Assists in identifying actors, assets, threats, and mitigations.
  • Use Case: A project maintainer needs to prepare for their CNCF graduation application and must submit a security self-assessment. This Skill will walk them through gathering all necessary information and structuring it according to the TAG Security guidelines.

Quick Start

Use the security-self-assessment skill to begin documenting your project's security posture by following the official template and reviewer guide.

Frequently Asked Questions about security-self-assessment

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I document a project's security posture for CNCF graduation?

To document your security posture for CNCF graduation, you complete a comprehensive self-assessment questionnaire detailing your project's threat model, security practices, and operational requirements to satisfy TAG Security reviews.

What is a security self-assessment questionnaire for TAG Security?

A security self-assessment questionnaire is a structured document used to detail a project's security posture, threat modeling, and operational practices required for TAG Security reviews and graduation applications.

How do I create a threat model for a CNCF project security review?

You create a threat model for a CNCF security review by identifying project actors, assets, threats, and mitigations, then structuring this information according to official TAG Security templates and submission guidelines.

Does the TAG Security self-assessment require specific submission guidelines?

Yes, the TAG Security self-assessment requires strict adherence to official templates and submission guidelines to ensure the project's security posture and operational practices meet graduation review standards.

Can I use this process for any cloud native project compliance assessment?

This compliance assessment process is specifically designed for CNCF projects preparing for graduation, guiding them through TAG Security requirements rather than general cloud native compliance frameworks.

What steps are needed to complete a TAG Security self-assessment?

Completing a TAG Security self-assessment involves following a step-by-step process to gather information on your security posture and threat model, then structuring it within the official questionnaire template for submission.