security-review

Identify security gaps and produce a structured security review deliverable.

2|Updated Mar 15, 2026
One-click install
npx skills add https://github.com/Modular-Earth-LLC/solutions-architecture-agent --skill security-review-modular-earth-llc
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: security-review
Source: https://github.com/Modular-Earth-LLC/solutions-architecture-agent/tree/main/skills/security-review
Command: npx skills add https://github.com/Modular-Earth-LLC/solutions-architecture-agent --skill security-review-modular-earth-llc

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill helps organizations assess and document security posture for complex solutions, ensuring regulatory alignment and auditable artifacts.

Core Features & Use Cases

  • STRIDE threat modeling across the architecture and data flows
  • Compliance mapping for HIPAA, SOC 2, CCPA, GLBA, PCI-DSS
  • Defense-in-depth architecture guidance and guardrails
  • AI-specific security controls and governance considerations
  • Output-ready artifacts for risk reviews and audits

Quick Start

Initiate a STANDARD-depth security review for the current architecture and generate the security deliverables.

Frequently Asked Questions about security-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a STRIDE threat model for my application architecture?▼

To perform a STRIDE threat model, apply the methodology across your architecture and data flows to identify security gaps, spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege risks.

Can I use this security review to map compliance for HIPAA, SOC 2, and PCI-DSS?▼

Yes, you can use this security review to map compliance for HIPAA, SOC 2, CCPA, GLBA, and PCI-DSS. It validates your security posture against these non-functional requirements and generates output-ready compliance artifacts.

What is the best way to document defense-in-depth guardrails for an auditable risk review?▼

Documenting defense-in-depth guardrails involves generating structured artifacts like threat models and compliance mappings. This approach outlines remediation steps with risk-based priorities to produce auditable deliverables.

Does this security assessment include AI-specific controls and governance considerations?▼

Yes, this security assessment includes AI-specific security controls and governance considerations. It scopes the evaluation to your project's architecture to identify risks and validate the security posture of AI components.

How do I generate structured remediation steps with risk-based priorities after a security audit?▼

To generate structured remediation steps after a security audit, validate the security posture against non-functional requirements. This process outlines risk-based priorities and produces artifacts like threat models and guardrails.

When do I need threat modeling and compliance mapping for my system architecture?▼

You need threat modeling and compliance mapping when assessing complex solutions for regulatory alignment. It helps identify security gaps, ensures auditable artifacts are produced, and validates the architecture's defense-in-depth posture.