
Triage a dependency CVE using local repo evidence and remediation guidance.
Review workflow for AI/LLM output usage to prevent over-trust, injection, and unsafe automation.
Workflow for preventing secret leaks and sensitive logging (PII/credentials) and adding redaction defaults.
Lightweight, repeatable threat modeling for a feature or service with prioritized mitigations.
Analyze repository-grounded identity, access control, and authorization design with evidence-first reporting and script-validated Mermaid diagrams.
Analyze repository-grounded identity, access control, and authorization design with evidence-first reporting and script-validated Mermaid diagrams.
Triage a dependency CVE using local repo evidence and remediation guidance.
Use this skill when creating or editing GitHub Copilot customization Markdown files (agent profiles, prompt files, instruction files, and skills).
Repeatable process for an application security code review that produces prioritized findings and fix guidance.
Threat model a system, feature, service, or PR using Shostack's 4Q workflow, evidence-first analysis, risk scoring, and CLI-friendly Mermaid helper scripts.
Threat model a system, feature, service, or PR using Shostack's 4Q workflow, evidence-first analysis, risk scoring, and CLI-friendly Mermaid helper scripts.
Workflow to review authentication and authorization flows (sessions, tokens, RBAC/ABAC) and produce fix guidance.
Process for tightening input validation, canonicalization, and safe parsing to prevent injection and logic abuse.
Standard validation checklist to prove a security fix works and doesn’t regress behavior.