Identify and analyze security threats. Use when designing systems, reviewing architecture, or assessing risk. Covers STRIDE methodology.
.claude/rules/security.md — Critical and High findings MUST be fixed before merge.Beyond STRIDE, include this class whenever the design under review has a tool/model boundary:
.claude/rules/security.md's "Untrusted Content & Prompt Injection" section## Asset: User Database
### Threats
| Threat | Type | Severity | Remediation |
|--------|------|----------|--------------|
| SQL Injection | Tampering | High | Parameterized queries |
| Data Breach | Info Disclosure | Critical | Encryption at rest, access logging |
Search for places (restaurants, cafes, etc.) via Google Places API proxy on localhost.
Interact with GitHub using the `gh` CLI. Use `gh issue`, `gh pr`, `gh run`, and `gh api` for issues, PRs, CI runs, and advanced queries.
Create or update AgentSkills. Use when designing, structuring, or packaging skills with scripts, references, and assets.
Start voice calls via the OpenClaw voice-call plugin.
Notion API for creating and managing pages, databases, and blocks.
Gemini CLI for one-shot Q&A, summaries, and generation.
Category:developer