APPLICATION SECURITY & THREAT MODELING

Use this skill when the work involves authentication, authorization, trust boundaries, sensitive data, input validation, or vulnerability assessment. Activated when designing or modifying AuthN/AuthZ flows; handling or storing PII, financial, or health data; processing user input or file uploads; integrating with third-party APIs; designing system boundaries; reviewing pull requests (implicitly always active); or when the user mentions security concerns, vulnerabilities, or asks for a security audit. Examples: "is this secure?", "audit this for vulnerabilities", "how should I handle auth?", "is this input validation sufficient?", "what are the security risks here?", mentions of XSS, CSRF, SQLi, IDOR. Security is ALWAYS active as a secondary lens during code review and architecture design — never skip it.

Bilal140202 Updated

File contents

Bilal140202/the-lord-of-the-skills/tree/main/skills/mordor/claude-code/Kingdaddy007__my-os commit b4abbfc2c8

Frequently asked questions

npx skillmds@latest add bilal140202/application-security-threat-modeling