en un clic
agentic-security-lab
agentic-security-lab contient 8 skills collectées depuis theagenticguy, avec une couverture métier par dépôt et des pages de détail sur le site.
Skills dans ce dépôt
Big-Sleep variant analysis. Given a recently-fixed bug shape (the lines added/removed in a patch), find more code in the repository that has the same shape and is likely to carry the same defect. Reports variants linked to their seed. Deny-by-default: only the allowed_tools below are permitted.
Review a code diff or corpus for security vulnerabilities grounded in the supplied threat model. Reads code semantically, forms hypotheses, verifies them, and emits scored findings as a single JSON code block. Deny-by-default: only the allowed_tools below are permitted.
Given an architecture description or diagram, produce a STRIDE threat model plus attack trees as YAML. Use when the user asks to threat model a system.
Triage a candidate finding by deciding whether the vulnerable code is reachable from an untrusted entry point, producing the reachability axis (0-1) that feeds asec-confidence. Use when the user asks to triage a finding or assess exploitability.
Review a git diff for vulnerabilities by running Semgrep and CodeQL, then emit structured findings. Use when the user asks for a security review of a diff/PR.
Given an architecture description, diagram, or repo, produce a Phase-Zero STRIDE threat model plus attack trees as YAML conforming to asec-threat-model schema. Use when the user asks to bootstrap or create a threat model for a system.
Critique an existing threat model for completeness and rigor — missing STRIDE categories, unjustified skips, weak mitigations, ungrounded likelihood/impact. Use when the user asks to review, critique, or red-team a threat-model.yaml.
Compare two threat-model.yaml revisions and report what changed — added or