원클릭으로
iriusrisk-cli
iriusrisk-cli에는 iriusrisk에서 수집한 skills 12개가 있으며, 저장소 수준 직업 범위와 사이트 내 skill 상세 페이지를 제공합니다.
이 저장소의 skills
Analyze mixed repositories (application code + infrastructure + policies + docs) to extract ALL components for ONE unified threat model. Use when analyzing codebases with multiple source types for threat modeling. Architecture modeling only - do NOT identify vulnerabilities.
Step-by-step instructions for creating IriusRisk threat models (OTM files). Use when creating or updating threat models. Covers validation, component mapping, trust zones, and complete workflow from analysis to import.
Detailed guidance on OTM component layout and positioning. Use when creating initial layouts from scratch or updating existing layouts. Covers component sizes, spacing, nesting hierarchies, and cascading size calculations.
Analyze source code to answer IriusRisk questionnaires that refine threat models based on actual implementation. Use after creating threat model to reduce false positives and improve accuracy. Requires thorough code analysis.
Trigger point for architecture, design, or system structure reviews. Use when user asks to review architecture, design, or understand system structure. Guides you to check for existing threat models first.
Complete workflow instructions for IriusRisk threat modeling. Use when starting any threat modeling task. Provides decision logic for using existing threat models, creating new ones, and when to ask permission.
Help developers assess security impact of their work and recommend threat modeling when appropriate. Use when developer is planning changes or asks about security. Respects autonomy and workflow while providing guidance.
Analyze IriusRisk-generated threats and countermeasures from JSON files. Use when user asks about threats, security issues, or wants to understand security findings. Read and explain findings, prioritize by risk, provide implementation guidance.
Orchestrate comprehensive CI/CD security reviews combining version comparison, control verification, risk analysis, and reporting. Use when running automated CI/CD pipeline security checks or when user requests full security assessment.
Compare different states of a threat model to identify architectural and security changes. Use when reviewing pull requests for security impacts, detecting drift from approved baselines, or auditing historical changes. Returns structured diff for interpretation.
Verify that security controls (countermeasures) linked to issue tracker tasks are correctly implemented in code. Use when reviewing PRs that claim to implement specific security controls or validating documented controls match implementation.
Detailed validation rules for OTM files. Use when validating trust zone IDs, component types, and filtering deprecated components. Critical for preventing import failures.