Install any skill in seconds. Free to start, no credit card required.
Get Started Free →/cs:ciso-review <plan> — Risk-paranoid interrogation of any plan that touches data, compliance, or production access. Use when launching features that handle customer data, before a SOC 2 / ISO audit, or after any incident or near-miss.
| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-01 | ✗→✓ | ▲ Improved | 7% | 0% |
| case-03 | ✗→✓ | ▲ Improved | -3% | 0% |
| case-11 | ✗→✓ | ▲ Improved | -28% | 0% |
| case-13 | ✗→✓ | ▲ Improved | -39% | 0% |
| case-14 | ✗→✓ | ▲ Improved | -5% | 0% |
Command: /cs:ciso-review <plan>
The risk-paranoid threat-modeler. Six questions before any production change that touches customer data or compliance scope.
What's the STRIDE threat model for this system, and which threat is most likely?
If this is fully compromised, what data is exposed and how many users are affected?
What signals indicate compromise, and how long until they're triggered (MTTD)?
Is there an IR runbook for this scenario, and has it been tabletop-tested?
What's the regulator notification window if this scenario occurs?
Which third-party vendors are in scope, and what's their security posture?
bashpython ../../../skills/ciso-advisor/scripts/risk_quantifier.py python ../../../skills/ciso-advisor/scripts/compliance_tracker.py
markdown# CISO Review: <plan> **Date:** YYYY-MM-DD ## Threat Model - Top threat: <STRIDE category> — <description> - Likelihood: H/M/L | Impact: H/M/L - ALE: $X / year ## Blast Radius - Data exposed (worst case): <description> - Users affected: N - Estimated cost: $X ## Detection - MTTD target: X hours - Current MTTD: X hours - Detection rule: <name> ## Response - IR runbook: ✅ / ❌ - Last tabletop: <date> ## Regulatory - Frameworks in scope: SOC 2 / ISO 27001 / HIPAA / GDPR - Notification window: X hours/days ## Vendors - New vendors added: N - DPAs signed: N / N - Security reviews complete: N / N ## Verdict 🟢 SHIP | 🟡 MITIGATE THEN SHIP | 🔴 BLOCK
/cs:cto-review — architecture alignment/cs:gc-review — DPA, regulatory implications/cs:decide — log risk acceptance/cs:boardroom — for CRITICAL riskscs-ciso-advisorciso-advisor../../../../ra-qm-team/Version: 1.0.0
Other measured skills in the registry, with their headline benchmark lift.