speckit-security-review-followup

Convert security review findings into backlog-ready remediation and technical debt plans.

2|Updated Jan 6, 2026
One-click install
npx skills add https://github.com/NUMU-IO/NUMU-api --skill speckit-security-review-followup-numu-io
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: speckit-security-review-followup
Source: https://github.com/NUMU-IO/NUMU-api/tree/main/.agents/skills/speckit-security-review-followup
Command: npx skills add https://github.com/NUMU-IO/NUMU-api --skill speckit-security-review-followup-numu-io

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill turns security review findings into practical follow-up work so teams can respond quickly, avoid duplicated effort, and keep unresolved risks visible.

Core Features & Use Cases

  • Remediation Planning: Converts findings into immediate implementation tasks with clear acceptance criteria.
  • Technical Debt Tracking: Defers lower-priority issues with a documented rationale and a specific revisit trigger.
  • Deduplication and Context Awareness: Checks existing planning artifacts and project memory so already-covered issues are not tracked twice.
  • Use Case: A security reviewer pastes a list of findings, and this Skill produces a backlog-ready plan that separates urgent fixes, deferred debt, and already resolved items.

Quick Start

Use the speckit-security-review-followup skill to turn the latest security review findings into an actionable follow-up plan with remediation tasks, technical debt entries, and deduplicated coverage notes.

Frequently Asked Questions about speckit-security-review-followup

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I turn security review findings into actionable remediation tasks?

Security review findings are converted into backlog-ready remediation tasks with clear acceptance criteria, separating urgent fixes from deferred technical debt and already resolved items.

What is the best way to track technical debt deferred from a security review?

Deferred technical debt from security reviews is tracked with a documented rationale and a specific revisit trigger, ensuring lower-priority issues remain visible and are addressed at the appropriate time.

How do I deduplicate security findings against an existing project backlog?

Deduplication checks existing planning artifacts and project memory to prevent already-covered security issues from being tracked twice, ensuring unresolved risks are visible without duplicated effort.

Can I use this security review followup process with any Spec-Kit project?

This process applies to Spec-Kit projects that need backlog-ready remediation, severity-based triage, and preservation of secure patterns for reviewable implementation work.

How are security findings triaged when creating a remediation plan?

Security findings undergo severity-based triage to categorize issues into immediate implementation tasks, deferred technical debt entries, or deduplicated coverage notes for already resolved items.