What problem does it solve?
This Skill provides an adversarial, security-first review of products, architectures, and code to identify realistic attack scenarios, missing controls, and supply chain risks prior to production rollout. It translates qualitative concerns into structured, evidence-backed findings so teams can make informed, defensible release decisions.
Core Features & Use Cases
- Adversarial threat mapping: Walks through data flows and maps concrete attack vectors to observed evidence.
- Structured output for triage: Produces a JSON assessment with verdicts, severity, mitigations, missing controls, and conditional approvals for security teams and auditors.
- Supply chain and incident focus: Evaluates dependencies, CI/CD artifacts, and incident response maturity alongside runtime exposure.
- Use Case: Use during pre-launch reviews, pull request audits, or third-party tool evaluations to get an actionable checklist of security gaps and required mitigations.
Quick Start
Review the provided architecture notes or code and return a structured JSON threat assessment that lists realistic attack scenarios, evidence, severity, mitigations, missing controls, and any conditions required for approval.