security

Guide security architecture design with STRIDE threat modeling and compliance assessments.

1|Updated Dec 31, 2025
One-click install
npx skills add https://github.com/tomas-u/claude-skills --skill security-tomas-u
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security
Source: https://github.com/tomas-u/claude-skills/tree/main/security
Command: npx skills add https://github.com/tomas-u/claude-skills --skill security-tomas-u

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Security architecture decisions are often ad-hoc and error-prone. This skill provides structured, architecture-level guidance to design secure systems, perform threat modeling, and assess compliance.

Core Features & Use Cases

  • Security architecture design and validation
  • Threat modeling (STRIDE) and risk assessment
  • Compliance assessment (OWASP, NIS2, GDPR, PCI DSS, SOC 2)
  • Infrastructure and API security pattern guidance
  • Incident response planning and security governance
  • Use case: Pre-production security review for new microservices platform with a security roadmap and remediation plan

Quick Start

Load this skill to perform a high-level security architecture review and threat model for your platform.

Frequently Asked Questions about security

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform threat modeling for a microservices platform?

Threat modeling for a microservices platform uses the STRIDE methodology to identify threats across infrastructure and APIs, assess risks, and produce a remediation plan and security roadmap. This skill structures the review for cloud, on-prem, and hybrid environments.

What is STRIDE threat modeling and when do I need it?

STRIDE threat modeling is a structured method to identify spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege risks. You need it during pre-production security reviews and architecture design to ensure systems are secure by design.

How do I assess compliance with ISO 27001 and NIS2 during architecture design?

Assessing compliance with ISO 27001 and NIS2 involves mapping security architecture controls against framework requirements to identify gaps. This skill guides governance, risk prioritization, and security controls strategy for cloud, on-prem, and hybrid infrastructure.

Can I use this for security architecture reviews in hybrid cloud environments?

Yes, you can use this for security architecture reviews in hybrid cloud environments. It provides structured guidance for infrastructure and API security patterns, validating designs and prioritizing risks across cloud, on-prem, and hybrid deployments.

What is the best way to map OWASP risks into a security architecture?

The best way to map OWASP risks into a security architecture is to align threat modeling outputs with security controls strategy and compliance frameworks. This skill translates OWASP findings into prioritized remediation plans and governance policies.

How do I plan incident response and security governance for new APIs?

Planning incident response and security governance for APIs involves defining security architecture patterns, risk prioritization, and compliance controls. This skill helps structure governance frameworks and incident response plans alongside threat modeling outputs.