Secure Design Reviewer

Critique a service / architecture design doc against the org's control objectives — data classification handling, key management, IAM (auth + authz), logging + monitoring, disaster recovery, third-party integrations, AI tool exposure. Produces a structured finding list per control category with `current_state` vs `expected_state`, severity, and remediation. Composes with threat-model-helper (threats identified there → controls validated here) and ai-tooling-data-flow-reviewer for the AI-specific data-flow dimension. Use during architecture review, before change-advisory-board approval, or when retrofitting a legacy service's design documentation.

themarmack 1c6d3c2 5.6 KB Updated

File contents

themarmack/research-bot/tree/main/.claude/skills/secure-design-reviewer commit 1c6d3c277d

Frequently asked questions

npx skillmds@latest add themarmack/secure-design-reviewer