Install any skill in seconds. Free to start, no credit card required.
Get Started Free →/cs:ciso-review <plan> — Risk-paranoid interrogation of any plan that touches data, compliance, or production access. Use when launching features that handle customer data, before a SOC 2 / ISO audit, or after any incident or near-miss.
.claude/skills/alirezarezvani-ciso-review/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-01 | ✗→✓ | ▲ Improved | 6% | 0% |
| case-02 | ✗→✓ | ▲ Improved | 6% | 0% |
| case-04 | ✗→✓ | ▲ Improved | -15% | 0% |
| case-05 | ✗→✓ | ▲ Improved | 4% | 0% |
| case-06 | ✗→✓ | ▲ Improved | 45% | 0% |
Command: /cs:ciso-review <plan>
The risk-paranoid threat-modeler. Six questions before any production change that touches customer data or compliance scope.
What's the STRIDE threat model for this system, and which threat is most likely?
If this is fully compromised, what data is exposed and how many users are affected?
What signals indicate compromise, and how long until they're triggered (MTTD)?
Is there an IR runbook for this scenario, and has it been tabletop-tested?
What's the regulator notification window if this scenario occurs?
Which third-party vendors are in scope, and what's their security posture?
bashpython ../../../c-level-advisor/skills/ciso-advisor/scripts/risk_quantifier.py python ../../../c-level-advisor/skills/ciso-advisor/scripts/compliance_tracker.py
markdown# CISO Review: <plan> **Date:** YYYY-MM-DD ## Threat Model - Top threat: <STRIDE category> — <description> - Likelihood: H/M/L | Impact: H/M/L - ALE: $X / year ## Blast Radius - Data exposed (worst case): <description> - Users affected: N - Estimated cost: $X ## Detection - MTTD target: X hours - Current MTTD: X hours - Detection rule: <name> ## Response - IR runbook: ✅ / ❌ - Last tabletop: <date> ## Regulatory - Frameworks in scope: SOC 2 / ISO 27001 / HIPAA / GDPR - Notification window: X hours/days ## Vendors - New vendors added: N - DPAs signed: N / N - Security reviews complete: N / N ## Verdict 🟢 SHIP | 🟡 MITIGATE THEN SHIP | 🔴 BLOCK
/cs:cto-review — architecture alignment/cs:gc-review — DPA, regulatory implications/cs:decide — log risk acceptance/cs:boardroom — for CRITICAL riskscs-ciso-advisorciso-advisor../../../ra-qm-team/Version: 1.0.0
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | fail→pass | 32,831 | 29,297 | -11% | 1 | 1 | 0% | 4,695 | 4,973 | +6% | 0 | 0 | — |
case-02 | fail→pass | 38,791 | 27,947 | -28% | 1 | 1 | 0% | 5,252 | 5,567 | +6% | 0 | 0 | — |
case-03 | fail→fail | 49,186 | 28,170 | -43% | 1 | 1 | 0% | 8,254 | 5,463 | -34% | 0 | 0 | — |
case-04 | fail→pass | 33,948 | 25,435 | -25% | 1 | 1 | 0% | 5,228 | 4,429 | -15% | 0 | 0 | — |
case-05 | fail→pass | 25,557 | 17,182 | -33% | 1 | 1 | 0% | 3,437 | 3,573 | +4% | 0 | 0 | — |
case-06 | fail→pass | 27,551 | 28,500 | +3% | 1 | 1 | 0% | 3,176 | 4,600 | +45% | 0 | 0 | — |
case-07 | fail→pass | 21,582 | 24,863 | +15% | 1 | 1 | 0% | 3,425 | 4,171 | +22% | 0 | 0 | — |
case-08 | fail→pass | 28,106 | 21,975 | -22% | 1 | 1 | 0% | 3,480 | 4,494 | +29% | 0 | 0 | — |
case-09 | fail→pass | 24,877 | 20,077 | -19% | 1 | 1 | 0% | 3,332 | 3,985 | +20% | 0 | 0 | — |
case-10 | fail→fail | 17,966 | 28,139 | +57% | 1 | 1 | 0% | 2,932 | 4,398 | +50% | 0 | 0 | — |
case-11 | fail→fail | 23,119 | 30,865 | +34% | 1 | 1 | 0% | 2,854 | 5,122 | +79% | 0 | 0 | — |
case-12 | fail→fail | 25,022 | 24,915 | -0% | 1 | 1 | 0% | 3,269 | 3,967 | +21% | 0 | 0 | — |
case-13 | fail→pass | 24,897 | 21,434 | -14% | 1 | 1 | 0% | 3,214 | 3,538 | +10% | 0 | 0 | — |
case-14 | fail→fail | 27,086 | 22,856 | -16% | 1 | 1 | 0% | 3,481 | 4,710 | +35% | 0 | 0 | — |
case-15 | fail→pass | 16,839 | 23,349 | +39% | 1 | 1 | 0% | 2,510 | 3,777 | +50% | 0 | 0 | — |
case-16 | fail→fail | 21,602 | 27,742 | +28% | 1 | 1 | 0% | 2,599 | 4,509 | +73% | 0 | 0 | — |
case-17 | fail→fail | 29,641 | 33,684 | +14% | 1 | 1 | 0% | 3,687 | 5,381 | +46% | 0 | 0 | — |
case-18 | fail→fail | 19,864 | 24,242 | +22% | 1 | 1 | 0% | 2,381 | 4,113 | +73% | 0 | 0 | — |
case-19 | fail→pass | 20,352 | 23,371 | +15% | 1 | 1 | 0% | 1,967 | 3,913 | +99% | 0 | 0 | — |
case-20 | pass→pass | 21,454 | 20,540 | -4% | 1 | 1 | 0% | 2,651 | 3,656 | +38% | 0 | 0 | — |
case-21 | pass→pass | 15,530 | 17,030 | +10% | 1 | 1 | 0% | 2,086 | 3,204 | +54% | 0 | 0 | — |
case-22 | pass→fail | 63,594 | 39,692 | -38% | 1 | 1 | 0% | 3,584 | 5,422 | +51% | 0 | 0 | — |
case-23 | fail→pass | 13,429 | 21,812 | +62% | 1 | 1 | 0% | 1,976 | 3,720 | +88% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 23 cases were attempted. The headline lift of +48 percentage points is the difference between those two pass rates over the 23 comparable cases. 2 cases got worse with the skill loaded, and they are included in that figure.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
| Model | Method | Date | Lift |
|---|---|---|---|
| gemini-3.6-flash | verified | 8/4/2026 | +21% |
Other measured skills in the registry, with their headline benchmark lift.