What problem does it solve? Interviewers and hiring teams often struggle to design security interview questions that test real understanding rather than memorized OWASP lists. This Skill provides a structured question bank and evaluation rubric for security engineering roles, helping interviewers probe vulnerability root causes, attack-defense experience, and security-business trade-offs. ## Core Features & Use Cases - Topic Coverage: Twelve security domains including injection, XSS/CSRF, SSRF, authentication, OAuth2/OIDC, cryptography, SDL, penetration testing, incident response, cloud/IAM, containers, and supply chain security. - Difficulty Ladders: Each topic provides a progression from fundamentals to real-world scenarios, with good questions, danger signals, and expected signals for scoring candidates. - Resume Hooks: Maps resume keywords (SRC, CTF, SDL, pentest, cloud security) to targeted follow-up questions that verify claimed experience. - Use Case: When a candidate's resume mentions penetration testing experience, use this Skill to generate questions about authorization scope, lateral movement paths, and report writing, then evaluate answers against the listed danger and expected signals. ## Quick Start Load this Skill when the job description or resume mentions security engineer, application security, penetration testing, SDL, or cloud security, then ask it to generate interview questions for the candidate's background.