Analyze repository-grounded identity, access control, and authorization design with evidence-first reporting and script-validated Mermaid diagrams.
Triage a dependency CVE using local repo evidence and remediation guidance.
Threat model a system, feature, service, or PR using Shostack's 4Q workflow, evidence-first analysis, risk scoring, and CLI-friendly Mermaid helper scripts.
Analyze repository-grounded identity, access control, and authorization design with evidence-first reporting and script-validated Mermaid diagrams.
Threat model a system, feature, service, or PR using Shostack's 4Q workflow, evidence-first analysis, risk scoring, and CLI-friendly Mermaid helper scripts.
Review workflow for AI/LLM output usage to prevent over-trust, injection, and unsafe automation.
Process for tightening input validation, canonicalization, and safe parsing to prevent injection and logic abuse.
Workflow for preventing secret leaks and sensitive logging (PII/credentials) and adding redaction defaults.