senior-security

Perform STRIDE threat modeling and vulnerability analysis for security reviews.

Updated Mar 12, 2026
One-click install
npx skills add https://github.com/Fantasia1999/claude-skills-zh --skill senior-security-fantasia1999
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: senior-security
Source: https://github.com/Fantasia1999/claude-skills-zh/tree/main/translations/engineering-team/senior-security
Command: npx skills add https://github.com/Fantasia1999/claude-skills-zh --skill senior-security-fantasia1999

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill provides a comprehensive toolkit for identifying, analyzing, and mitigating security vulnerabilities across the software development lifecycle, ensuring robust system defenses.

Core Features & Use Cases

  • Threat Modeling: Proactively identify potential security threats using methodologies like STRIDE.
  • Vulnerability Assessment: Detect and prioritize security weaknesses in applications and infrastructure.
  • Secure Architecture Design: Implement defense-in-depth and zero-trust principles.
  • Use Case: When designing a new web application, use this Skill to perform a STRIDE analysis on the data flow diagrams to identify potential threats and define mitigation strategies before development begins.

Quick Start

Use the senior-security skill to perform a threat model on the provided system architecture diagram.

Frequently Asked Questions about senior-security

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a STRIDE threat analysis on my system architecture?

Performing STRIDE threat analysis involves providing your system architecture diagram to trigger the toolkit, which proactively identifies potential security threats across data flows and defines targeted mitigation strategies.

What is the best way to conduct a vulnerability assessment for secure coding practices?

The best way to conduct a vulnerability assessment is using the security engineering toolkit to detect and prioritize security weaknesses in applications and infrastructure based on OWASP guidelines and secure coding practices.

Can I use this for CVE remediation and attack surface analysis?

Yes, you can use this for CVE remediation and attack surface analysis, as the comprehensive toolkit is explicitly triggered by queries related to security reviews, vulnerability assessments, and security best practices to fortify your systems.

How do I implement zero-trust and defense-in-depth principles in security architecture design?

Implementing zero-trust and defense-in-depth principles is achieved by applying the toolkit's security architecture design patterns, which integrate cryptographic patterns and OWASP guidelines to ensure robust system defenses.

Does this support penetration testing and security audits for web applications?

Yes, this supports penetration testing and security audits for web applications by providing a comprehensive security engineering toolkit that includes security scanning tools triggered by queries related to vulnerability assessments and security best practices.