security-planning

Installation
SKILL.md

Security Planning

This skill packages durable security-planning and plan-drift analysis used by Security Planner, Security Reviewer, and Code Review: operational bucket guidance, STRIDE analysis patterns, standards cross-references, NIST control-family references, security-specific backlog formats, and correlation of a Security Planner baseline with current security findings.

When to use

Use this skill when you need to:

  • Classify application components into the operational security buckets used during planning.
  • Evaluate threats with STRIDE-based analysis, including AI-specific extensions when raiEnabled is true.
  • Map bucket findings to standards references and control families without re-embedding long standard tables.
  • Derive security-specific backlog priorities and RAI work item categories for Phase 5 handoff.
  • Correlate a Security Planner baseline with caller-supplied current findings to identify validated controls, control drift, residual planned risks, newly introduced threats, and obsolete plan items.
  • Generate a dual-output TM7 model plus markdown report from a YAML/JSON threat-model spec for human-reviewed audit workflows.

Security plan drift analysis

Use the drift capability when a Security Planner baseline and current-state security findings already exist. It correlates supplied evidence only: it does not scan, profile, select security skills, verify findings, re-rate severity, invoke another agent, or modify source, plan, reviewer, backlog, or state artifacts.

Installs
31
GitHub Stars
1.5K
First Seen
Jun 19, 2026
security-planning — microsoft/hve-core