What problem does it solve? It helps teams identify and fix security weaknesses across applications, APIs, identities, cloud infrastructure, and software supply chains before attackers exploit them, replacing ad-hoc security reviews with a structured engineering workflow. ## Core Features & Use Cases - Threat Modeling & Risk Analysis: Maps assets, trust boundaries, attackers, and abuse cases, then prioritizes findings by exploitability and business impact. - Application & API Security Review: Audits authentication, authorization, session handling, input validation, and secrets against OWASP ASVS and OWASP Top 10 standards. - Supply Chain & Cloud Hardening: Assesses dependencies, SBOMs, CI/CD pipelines, containers, and cloud permissions, producing remediation plans and hardening checklists. - Use Case: Before launching a new SaaS API, use this Skill to build a threat model, review OAuth/OIDC token handling, scan dependencies for vulnerabilities, and deliver a prioritized remediation plan with an incident-response playbook. ## Quick Start Ask the AI to perform a security review and threat model of your application, covering authentication, API endpoints, dependencies, and cloud configuration, and to produce a prioritized remediation plan.