Derive security requirements from threat models and business context. Use when translating threats into actionable requirements, creating security user stories, or building security test cases.
Transform threat analysis into actionable security requirements.
Business Requirements → Security Requirements → Technical Controls
↓ ↓ ↓
"Protect customer "Encrypt PII at rest" "AES-256 encryption
data" with KMS key rotation"
| Type | Focus | Example | | ------------------ | ----------------------- | ------------------------------------- | | Functional | What system must do | "System must authenticate users" | | Non-functional | How system must perform | "Authentication must complete in <2s" | | Constraint | Limitations imposed | "Must use approved crypto libraries" |
| Attribute | Description | | ---------------- | --------------------------- | | Traceability | Links to threats/compliance | | Testability | Can be verified | | Priority | Business importance | | Risk Level | Impact if not met |
Full template library lives in references/details.md. Read that file when you need concrete templates for this skill.
npx skills add wshobson/security-requirement-extraction下载完整 Skill 目录,包含 SKILL.md 及所有相关文件
Use CodexBar CLI local cost usage to summarize per-model usage for Codex or Claude, including the current (most recent) model or a full model breakdown. Trigger when asked for model-level usage/cost data from codexbar, or when you need a scriptable per-model summary from codexbar cost JSON.
Set up and use 1Password CLI (op). Use when installing the CLI, enabling desktop app integration, signing in (single or multi-account), or reading/injecting/running secrets via op.
Create or update AgentSkills. Use when designing, structuring, or packaging skills with scripts, references, and assets.
OpenProse VM skill pack. Activate on any `prose` command, .prose files, or OpenProse mentions; orchestrates multi-agent workflows.
Control Philips Hue lights and scenes via the OpenHue CLI.
Transcribe audio via OpenAI Audio Transcriptions API (Whisper).
Category:developer