security-qa-scenarios
Installation
SKILL.md
Security QA Scenarios
Generate concrete negative and abuse-case tests from actors, objects, trust boundaries, state, inputs, time, and limits.
Process
- Inspect the changed behavior and data flow before listing risks.
- Check negative paths, bypasses, tenant/object boundaries, logs, cache, async jobs, and release impact where relevant.
- For review, report findings by severity with file references and concrete exploit or failure scenarios.
- For implementation, add controls and tests in the backend or trusted boundary; do not rely on frontend-only enforcement.
Evidence
Prefer code, tests, logs, config, API contracts, and data examples over assumptions.