security-phoenix-demo
- 7 skills
- 0 followers
- 1 day ago last updated
- ▌ Cti Domain Research · security-phoenix-demo bundleSearch for threat intelligence, CVEs, malware analysis, breach reports, and security research across 300+ curated security domains (BleepingComputer, Hacker News, Krebs, Unit42, Talos, CISA, Mandiant, Rapid7, Securelist, etc.). Use this skill whenever the user asks to: research a CVE or vulnerability, find what security vendors are saying about a threat actor or malware family, search security blogs, look up threat intelligence on a topic, find recent breach or ransomware reports, collect CTI for a MITRE technique, or push research into NotebookLM. Triggers for phrases like "search security sources", "find threat intel on X", "what are vendors saying about Y", "research CVE-XXXX", "look up malware Z", "collect CTI", "push to NotebookLM", or any domain-scoped web research request in a security context.
- ▌ Prd Generator · security-phoenix-demo bundleGenerate a full security-focused PRD (Product Requirements Document) from a plain-language feature description. Use this skill whenever someone wants to create a PRD, product spec, feature spec, requirements document, or says things like "write a PRD for", "create a spec for", "plan this feature", "document this feature", or "I need a requirements doc". The skill produces: (1) a structured PRD in a security-focused template format, (2) a Confluence page pushed to your configured space via Atlassian MCP (called directly), (3) a cursor-compatible .md plan file for .cursor/plans/, (4) a downloadable formatted markdown, (5) optionally: Linear/Asana tasks from the batch plan, Slack notification to stakeholders, Notion page mirror. Always use this skill for PRD and feature planning tasks.
- ▌ Opengrep Rule Generator · security-phoenix-demo bundleUse when the user wants to create opengrep/semgrep SAST rules, detect vulnerabilities in code, generate security scanning rules from CVEs or vulnerability descriptions, or asks about writing pattern-matching or taint-analysis rules for static analysis.
- ▌
- ▌
- ▌
- ▌ Security Reviewer · security-phoenix-demo bundleMulti-language security review for web apps, APIs, and CLIs. Use whenever code is added or modified — new endpoints, auth/RBAC changes, template or DOM rendering, outbound HTTP, dependency updates, IaC/config changes, or end-of-feature reviews. Covers Python, JavaScript, TypeScript, Go, Rust, Java/Kotlin, Ruby, C#/.NET, plus shared OWASP Top 10 and ASVS L1 logic. Triggers on phrases like "security review", "review this for security", "audit this code", "is this safe", "AppSec check", "threat-model this change", "supply chain risk", "before I merge", or whenever a senior engineer would pause to ask "what could go wrong here". Pairs with the `security-reviewer` subagent and the session-start / pre-bash / post-edit hooks shipped alongside it.