Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Use when the user asks for STRIDE threat modeling, DREAD risk scoring, data-flow-diagram threat analysis, or a quick secret scan — or when a security request needs routing to the right specialist skill (pen-testing, incident response, cloud posture, red team, AI security, threat hunting, secure code review). This skill owns threat modeling; everything else routes to a sibling.
.claude/skills/alirezarezvani-senior-security/SKILL.md| Model | Eval pass | Runs |
|---|---|---|
| gemini-3.1-pro-preview | 100% | 1 |
| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-03 | ✗→✓ | ▲ Improved | 40% | 0% |
| case-17 | ✗→✓ | ▲ Improved | 47% | 0% |
| case-04 | ✗→✓ | ▲ Improved | -30% | 0% |
| case-05 | ✗→✓ | ▲ Improved | -30% | 0% |
| case-06 | ✗→✓ | ▲ Improved | -40% | 0% |
This skill does exactly one job itself — STRIDE/DREAD threat modeling (plus a quick secret scan) — and routes every other security request to the specialist skill that owns that lane. Do not duplicate sibling content here; route instead.
| The user wants... | Route to | Why that skill owns it | |---|---|---| | Vulnerability assessment, pen-test methodology, OWASP Top 10 testing | ../security-pen-testing/ | Ships vulnerability_scanner.py + dependency_auditor.py with exit-code contracts | | Incident triage, SEV classification, forensics, containment | ../incident-response/ | SEV1–SEV4 taxonomy, NIST SP 800-61 phases, incident_triage.py | | Production outage command (non-security incidents) | ../incident-commander/ | Severity classifier + timeline + postmortem tools | | Security monitoring, CVE triage SLAs, compliance checks (SOC 2 etc.), security headers | ../senior-secops/ | security_scanner.py + compliance_checker.py, CVE SLA table | | Hostile/adversarial code review | ../adversarial-reviewer/ | 3-persona review with BLOCK/CONCERNS/CLEAN verdict | | Secure code review as part of general review | ../code-reviewer/ | Language dispatch + regression fixtures | | Cloud IAM escalation paths, S3 exposure, security groups | ../cloud-security/ | cloud_posture_check.py with per-check exit codes | | Threat hunting, IOC sweeps, anomaly detection | ../threat-detection/ | z-score anomaly + IOC staleness tooling | | Red-team engagement planning, ATT&CK kill chains | ../red-team/ | engagement_planner.py with authorization gate | | LLM/AI attack surface (prompt injection, poisoning) | ../ai-security/ | ATLAS-mapped ai_threat_scanner.py |
If the request spans lanes (e.g., "secure this new architecture"), do the threat model here first — its output (prioritized threats + mitigations) tells you which siblings to load next. Never bulk-load multiple security skills speculatively.
bash python3 scripts/threat_modeler.py --component "User Authentication" --assets "credentials,sessions" --json --output threats.json Output: per-threat STRIDE category, DREAD score (Damage, Reproducibility, Exploitability, Affected users, Discoverability — each 1–10), and suggested mitigations. Repeat per DFD element; --interactive walks scoping questions; --list-threats shows the threat database.
threats.json by DREAD score descending; everything ≥ 7 average needs a named mitigation owner before the design ships. Map each mitigation to the responsible sibling lane (e.g., IAM threats → cloud-security, injection threats → code-reviewer).bash python3 scripts/secret_scanner.py /path/to/project --format json --severity high 20+ patterns (AWS keys, GitHub tokens, private keys, generic credentials). Any critical/high finding blocks merge until rotated and moved to a secret manager.
| DFD Element | S | T | R | I | D | E | |-------------|---|---|---|---|---|---| | External Entity | X | | X | | | | | Process | X | X | X | X | X | X | | Data Store | | X | X | X | X | | | Data Flow | | X | | X | X | |
(S=Spoofing→authn, T=Tampering→integrity, R=Repudiation→audit logs, I=Info Disclosure→encryption/access control, D=DoS→rate limiting/redundancy, E=Elevation→least privilege.)
| Document | Content | |----------|---------| | references/threat-modeling-guide.md | STRIDE methodology, attack trees, DREAD scoring, DFD creation | | references/security-architecture-patterns.md | Zero Trust, defense-in-depth, authentication patterns, API security | | references/cryptography-implementation.md | AES-GCM, Ed25519, password hashing (Argon2id), key management |
The architecture and crypto references are kept because no sibling ships them; for operating those controls (scanning, compliance, monitoring) still route to senior-secops.
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | fail→fail | 17,868 | 25,934 | +45% | 1 | 1 | 0% | 3,587 | 1,579 | -56% | 0 | 0 | — |
case-02 | fail→fail | 25,289 | 21,817 | -14% | 1 | 1 | 0% | 3,728 | 4,046 | +9% | 0 | 0 | — |
case-03 | fail→pass | 19,463 | 23,133 | +19% | 1 | 1 | 0% | 3,757 | 5,262 | +40% | 0 | 0 | — |
case-17 | fail→pass | 7,203 | 3,282 | -54% | 1 | 1 | 0% | 1,203 | 1,773 | +47% | 0 | 0 | — |
case-04 | fail→pass | 16,136 | 4,049 | -75% | 1 | 1 | 0% | 2,762 | 1,945 | -30% | 0 | 0 | — |
case-05 | fail→pass | 18,430 | 6,318 | -66% | 1 | 1 | 0% | 3,182 | 2,233 | -30% | 0 | 0 | — |
case-06 | fail→pass | 16,482 | 3,922 | -76% | 1 | 1 | 0% | 3,300 | 1,971 | -40% | 0 | 0 | — |
case-07 | fail→pass | 13,329 | 11,565 | -13% | 1 | 1 | 0% | 2,496 | 3,404 | +36% | 0 | 0 | — |
case-08 | pass→pass | 12,307 | 7,153 | -42% | 1 | 1 | 0% | 2,120 | 2,600 | +23% | 0 | 0 | — |
case-09 | pass→pass | 10,191 | 5,085 | -50% | 1 | 1 | 0% | 1,757 | 2,080 | +18% | 0 | 0 | — |
case-10 | pass→pass | 11,954 | 11,006 | -8% | 1 | 1 | 0% | 2,101 | 3,097 | +47% | 0 | 0 | — |
case-11 | fail→pass | 12,150 | 2,285 | -81% | 1 | 1 | 0% | 2,491 | 1,639 | -34% | 0 | 0 | — |
case-12 | pass→pass | 8,204 | 5,314 | -35% | 1 | 1 | 0% | 1,407 | 2,073 | +47% | 0 | 0 | — |
case-13 | fail→pass | 15,390 | 2,325 | -85% | 1 | 1 | 0% | 2,548 | 1,578 | -38% | 0 | 0 | — |
case-14 | pass→pass | 5,226 | 3,203 | -39% | 1 | 1 | 0% | 949 | 1,863 | +96% | 0 | 0 | — |
case-15 | fail→fail | 6,386 | 2,953 | -54% | 1 | 1 | 0% | 1,070 | 1,694 | +58% | 0 | 0 | — |
case-16 | fail→pass | 16,032 | 9,759 | -39% | 1 | 1 | 0% | 2,776 | 2,763 | -0% | 0 | 0 | — |
case-18 | fail→pass | 18,090 | 5,156 | -71% | 1 | 1 | 0% | 3,454 | 2,066 | -40% | 0 | 0 | — |
case-19 | fail→pass | 7,943 | 2,896 | -64% | 1 | 1 | 0% | 1,425 | 1,719 | +21% | 0 | 0 | — |
case-20 | fail→fail | 10,062 | 6,250 | -38% | 1 | 1 | 0% | 1,682 | 2,333 | +39% | 0 | 0 | — |
case-21 | fail→pass | 12,909 | 5,817 | -55% | 1 | 1 | 0% | 2,283 | 2,305 | +1% | 0 | 0 | — |
case-22 | fail→pass | 13,991 | 6,383 | -54% | 1 | 1 | 0% | 2,271 | 2,300 | +1% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted, and 21 counted toward the lift figure. The other 1 produced results that are not comparable between the two arms, so they are excluded from the headline rather than averaged into it. The headline lift of +59 percentage points is the difference between those two pass rates over the 21 comparable cases.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.