What problem does it solve? Shipping code without a structured security review leaves applications exposed to injection attacks, broken access control, auth bypasses, and compliance gaps. This Skill performs a systematic, multi-phase application security audit that produces concrete findings with file-and-line references and executable fixes. ## Core Features & Use Cases - STRIDE Threat Modeling: Maps attack surfaces, trust boundaries, and data flow threats per service with risk-scored threat matrices. - OWASP Top 10 Code Audit: Reviews every endpoint and code path for injection, broken access control, cryptographic failures, and SSRF, with each finding tied to a specific file and line. - Auth, Data & Supply Chain Review: Traces authentication flows, audits token management and RBAC policies, inventories PII across databases, logs, and caches, and evaluates dependencies with contextual severity re-evaluation. - Remediation Plan & Pen Test Suite: Delivers prioritized fixes with before/after code, verification tests, an API fuzzing configuration, and per-service attack scenarios. - Use Case: After implementing and testing a multi-service web application, run this Skill in the hardening phase to receive a full security audit report, critical vulnerability fixes with code, and a recurring audit schedule before launch. ## Quick Start Ask the agent to run a full security audit of the services and frontend code, covering threat modeling, OWASP review, auth flows, data security, and dependencies, and produce a prioritized remediation plan.