security-engineer

Identify and remediate application security vulnerabilities across code, infrastructure, and dependencies.

Updated Mar 25, 2026
One-click install
npx skills add https://github.com/ouakar/ubinarys-dental --skill security-engineer-ouakar
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: security-engineer
Source: https://github.com/ouakar/ubinarys-dental/tree/main/skills/forgewright/skills/security-engineer
Command: npx skills add https://github.com/ouakar/ubinarys-dental --skill security-engineer-ouakar

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Security-engineer provides production-grade application security audits, threat modeling, and remediation planning across code, dependencies, and infrastructure.

Core Features & Use Cases

  • Comprehensive threat modeling (STRIDE) and OWASP Top 10 code audit guidance
  • End-to-end auth, data security, and supply chain reviews with actionable remediation plans
  • Per-service findings with traceability to exact files and lines

Quick Start

Run a full security assessment across the codebase to generate a prioritized remediation plan.

Frequently Asked Questions about security-engineer

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a security audit on my codebase using OWASP Top 10 guidelines?▼

Perform a production-grade security audit by applying OWASP Top 10 code review and STRIDE threat modeling across full-stack applications, microservices, and AI-enabled workflows to identify vulnerabilities. It delivers per-service findings with exact file and line traceability.

What is STRIDE threat modeling and how does it apply to microservices security?▼

STRIDE threat modeling is a framework for identifying security threats across code, infrastructure, and dependencies. It enforces this methodology during microservices security reviews to map vulnerabilities and generate comprehensive remediation plans.

Can I use this security audit workflow in my CI/CD pipelines?▼

Yes, you can use this security audit workflow in CI/CD pipelines. It is explicitly designed to identify and remediate application security vulnerabilities across code, infrastructure, and dependencies within production and CI/CD environments.

How do I generate a Software Bill of Materials (SBOM) and check supply chain dependencies?▼

Generate an SBOM and review supply chain security by auditing your application dependencies. The audit process includes end-to-end supply chain reviews and SBOM generation to identify vulnerable components and provide actionable remediation plans.

Does this security audit cover data protection and RBAC remediation planning?▼

Yes, the audit covers RBAC and data protection remediation planning. It enforces end-to-end auth and data security reviews across your codebase, providing a prioritized remediation plan across six comprehensive phases.

What is the best way to remediate security vulnerabilities found during a code review?▼

The best way to remediate security vulnerabilities is to follow a prioritized remediation plan generated after a full code review. It maps identified threats to actionable steps across six phases, ensuring comprehensive vulnerability resolution.