PM Security

Hands-on application & operational security skills: Threat Model (STRIDE), Security Review, Vulnerability Triage (CVSS), Security Incident Response, and Pentest Report. Defensive security and authorized testing for systems you own or are permitted to assess.

by @mohitagw15856 6 skills

Skills in this plugin

6
  1. Vuln Triage · mohitagw15856
    Triage a vulnerability or scanner finding — assess real severity, exploitability, and how urgently to fix. Use when asked to triage a CVE, prioritize scanner/pentest findings, assess a vuln's risk, or decide what to patch first. Produces a triage verdict: CVSS-informed severity adjusted for your context, exploitability, real risk, a fix/mitigation, and an SLA — so you fix what matters, not just what's red.
    2 installs
  2. Threat Model · mohitagw15856
    Threat-model a system or feature to find where it could be attacked, before you build it. Use when asked to threat-model, do a security design review, document security risks, identify attack surface, or apply STRIDE to a design. Produces a structured threat model: assets, trust boundaries and data flows, threats enumerated by category (STRIDE), risk scores, prioritized mitigations, and residual-risk sign-off. Defensive security for systems you own or are authorized to assess.
    2 installs
  3. Skill Vetting · mohitagw15856
    Vet an agent skill before installing it — read the SKILL.md and any scripts for the red-flag patterns (credential access, obfuscation, exfiltration, prompt injection), audit its blast radius, and produce a risk-tiered verdict. Use when asked is this skill safe to install, vet this SKILL.md, review this skill from a marketplace, or check what this skill can do to my machine. Produces the risk classification with quoted evidence, the permission-surface audit, the red-flag checklist results, and an install/sandbox/reject recommendation.
    2 installs
  4. Pentest Report · mohitagw15856
    Write a clear penetration-test report from findings of an authorized engagement. Use when documenting a pentest, security assessment, or authorized red-team engagement — turning findings into a report clients act on. Produces an executive summary, scope & methodology, findings with severity/evidence/reproduction/remediation, and a risk-ranked remediation plan. For authorized testing only.
    2 installs
  5. Security Review · mohitagw15856
    Review a design, PR, or feature for security issues before it ships. Use when asked to do a security review, security-review a change/PR, or check a feature for vulnerabilities. Produces a structured review across the common risk areas (authn/authz, input handling, secrets, data exposure, dependencies), findings ranked by severity with concrete fixes, and a ship / fix-first verdict. For code and systems you own or are authorized to review.
    2 installs
  6. Security Incident Response · mohitagw15856
    Run or document a security incident response — contain, eradicate, recover, and learn. Use when responding to a breach/compromise/security incident, writing an IR plan or runbook, or producing a post-incident report. Produces a phase-by-phase response (triage, contain, eradicate, recover, post-incident) with the immediate actions, comms, evidence-handling, and a blameless review. For incidents on systems you own or defend.
    2 installs