senior-security

Conduct STRIDE threat modeling and security vulnerability analysis for software systems.

Updated Aug 23, 2026
One-click install
npx skills add https://github.com/SonPaier/carfect --skill senior-security-sonpaier
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: senior-security
Source: https://github.com/SonPaier/carfect/tree/main/.claude/skills/security
Command: npx skills add https://github.com/SonPaier/carfect --skill senior-security-sonpaier

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill addresses the critical need for robust security in software development by providing comprehensive tools and workflows for threat modeling, vulnerability analysis, secure architecture design, and incident response.

Core Features & Use Cases

  • Threat Modeling: Identify and analyze potential security threats using methodologies like STRIDE.
  • Secure Architecture: Design systems with defense-in-depth and Zero Trust principles.
  • Vulnerability Assessment: Scan and analyze code and applications for security weaknesses.
  • Incident Response: Provides structured workflows for handling security incidents.
  • Use Case: A development team is about to launch a new feature. They can use this Skill to conduct a threat model, review the architecture for security flaws, and plan for potential vulnerabilities before deployment.

Quick Start

Use the senior-security skill to conduct a threat model for the user authentication service.

Frequently Asked Questions about senior-security

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I conduct threat modeling using STRIDE for a new software feature?

Secure architecture design applies defense-in-depth and Zero Trust principles to ensure multiple layers of security controls exist. This Skill guides you in structuring systems so that every access request is continuously verified, reducing the attack surface across your network and applications.

What is the best way to perform vulnerability analysis and penetration testing on my application?

Vulnerability analysis and penetration testing are best performed using integrated security scanning tools and expert guidance. This Skill includes scanning utilities and cryptography patterns to proactively identify, assess, and help remediate security weaknesses in your code and applications.

How does incident response workflow integration handle active security vulnerabilities?

Incident response workflows handle active vulnerabilities by providing structured, step-by-step actions for detection, containment, eradication, and recovery. This Skill offers proactive defense strategies and incident response plans to systematically manage and mitigate security breaches as they occur.

Can I use this security engineering toolkit for OWASP guidance and cryptography pattern implementation?

Yes, you can use this security engineering toolkit for OWASP guidance and cryptography pattern implementation. It provides comprehensive resources for integrating standard security practices and cryptographic protections directly into your software development lifecycle.

Do I need a dedicated security team to use these vulnerability assessment and secure architecture tools?

You do not need a dedicated security team to use these vulnerability assessment and secure architecture tools. The Skill is designed to guide development teams through expert security workflows, enabling proactive defense and threat analysis without requiring specialized personnel.