What problem does it solve? Security reviews of application code, cloud architecture, and CI/CD pipelines often produce noisy scanner output or vague advice. This Skill performs a structured, senior-engineer-grade security assessment that separates confirmed issues from speculation, prioritizes by real exploitability and blast radius, and delivers concrete fixes engineering teams can ship. ## Core Features & Use Cases - Evidence-Based Findings: Every issue is labeled Confirmed, Likely, or Possible with severity ratings (Critical through Informational) tied to concrete evidence in your code, configs, or scan output. - Broad Domain Coverage: Reviews application code and APIs, AWS/Azure/GCP architecture and IAM, containers, Kubernetes, serverless, Terraform/CloudFormation/Bicep/Helm, CI/CD pipelines, and dependency or supply-chain risk. - Structured Remediation Reports: Produces a consistent report with findings, prioritization (fix now vs. schedule vs. accept with compensating controls), hardening recommendations, and mappings to OWASP, CWE, MITRE ATT&CK, and CIS Benchmarks. - Use Case: Point it at a Terraform module and Kubernetes manifests before deployment to catch public exposure, overbroad IAM roles, and privileged containers, then receive safer example configurations and validation steps for each finding. ## Quick Start Use the cloud-security-vulnerability-expert skill to review this Terraform configuration and Kubernetes deployment for exploitable security risks and prioritized remediations.