What problem does it solve? Security findings, compliance obligations, and vendor risks often lack a clear decision owner, leaving teams unsure whether a vulnerability blocks a release or goes to the backlog. This Skill provides CISO-level risk governance: severity classification, compliance obligation mapping, and structured security decision records. ## Core Features & Use Cases - Risk Classification: Categorizes vulnerabilities into P0–P3 severity levels with defined response timelines and release-blocking criteria. - Compliance Management: Maps GDPR, CNPD, LGPD, PCI-DSS, and ePrivacy obligations to jurisdictions and data processing activities. - Security Review Gates: Provides pre-release checklists for features touching auth, payments, PII, or multi-tenant data, plus vendor security approval criteria. - Use Case: A penetration test reveals a privilege escalation flaw before launch. Use this Skill to classify it as P1, feature-flag the affected surface, define the 24-hour remediation plan, and document the compliance impact. ## Quick Start Ask the AI to act as the CISO and classify the severity of a discovered vulnerability, then produce a security decision record with remediation steps.