security-pro

Identify cross-platform security risks via threat modeling and defense-in-depth guidance.

1|Updated Jul 3, 2026
One-click install
npx skills add https://github.com/truongnat/skills --skill security-pro
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: security-pro
Source: https://github.com/truongnat/skills/tree/main/skills/security-pro
Command: npx skills add https://github.com/truongnat/skills --skill security-pro

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Security guidance that helps teams perform threat modeling, secure design, and defense-in-depth planning across web, mobile, API, and backend stacks.

Core Features & Use Cases

  • Threat modeling across full stack to identify risks and map them to effective controls.
  • Guidance for secure design, authn/authz, secrets management, API and client hardening, and operational security signals, with clear handoffs to stack-specific skills.
  • Supports authorized self-assessment and risk reporting, referencing MITRE ATT&CK, OWASP practices, and OSI/TCP-IP concepts for context.

Quick Start

Perform a security review across a web/mobile/API stack by applying threat-modeling and defense-in-depth principles.

Frequently Asked Questions about security-pro

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform threat modeling across web, mobile, API, and backend architectures?▼

Threat modeling across web, mobile, API, and backend architectures involves identifying risks and mapping them to actionable controls. This Skill guides you through secure design and defense-in-depth planning using policy references.

What is defense-in-depth planning and how does it apply to cross-platform security?▼

Defense-in-depth planning for cross-platform security layers actionable controls across web, mobile, API, and backend stacks. It enforces server-side validation and references OSI/TCP-IP concepts to mitigate identified threats.

Can I use this for secure design and authorization guidance in my application?▼

Yes, you can use this for secure design and authorization guidance. It provides authn/authz support, secrets management, API hardening, and operational security signals with clear handoffs to stack-specific skills.

How do I map identified application security risks to effective controls?▼

To map application security risks to effective controls, the Skill references MITRE ATT&CK and OWASP practices. It identifies threats and delegates implementation to sibling skills like nextjs-pro or postgresql-pro.

Does this provide implementation details for Node.js or Next.js backend hardening?▼

No, it delegates backend hardening to sibling skills like nestjs-pro and nextjs-pro. It focuses on secure design, threat modeling, and enforcing server-side controls rather than writing implementation code.

When do I need a cross-platform security review for my full stack application?▼

You need a cross-platform security review when identifying risks across web, mobile, API, and backend layers. It supports authorized self-assessment, risk reporting, and establishes defense-in-depth guidance before deployment.