Skip to main content
在 Manus 中运行任何 Skill
一键导入
GitHub 仓库

iriusrisk-cli

iriusrisk-cli 收录了来自 iriusrisk 的 12 个 skills,并提供仓库级职业覆盖和站内 skill 详情页。

已收集 skills
12
Stars
3
更新
2026-02-19
Forks
1
职业覆盖
1 个职业分类 · 已分类 100%
仓库浏览

这个仓库中的 skills

analyze-source-material
信息安全分析师

Analyze mixed repositories (application code + infrastructure + policies + docs) to extract ALL components for ONE unified threat model. Use when analyzing codebases with multiple source types for threat modeling. Architecture modeling only - do NOT identify vulnerabilities.

2026-02-19
create-threat-model
信息安全分析师

Step-by-step instructions for creating IriusRisk threat models (OTM files). Use when creating or updating threat models. Covers validation, component mapping, trust zones, and complete workflow from analysis to import.

2026-02-19
otm-layout-guidance
信息安全分析师

Detailed guidance on OTM component layout and positioning. Use when creating initial layouts from scratch or updating existing layouts. Covers component sizes, spacing, nesting hierarchies, and cascading size calculations.

2026-02-19
questionnaire-guidance
信息安全分析师

Analyze source code to answer IriusRisk questionnaires that refine threat models based on actual implementation. Use after creating threat model to reduce false positives and improve accuracy. Requires thorough code analysis.

2026-02-10
architecture-design-review
信息安全分析师

Trigger point for architecture, design, or system structure reviews. Use when user asks to review architecture, design, or understand system structure. Guides you to check for existing threat models first.

2026-02-10
initialize-iriusrisk-workflow
信息安全分析师

Complete workflow instructions for IriusRisk threat modeling. Use when starting any threat modeling task. Provides decision logic for using existing threat models, creating new ones, and when to ask permission.

2026-02-10
security-development-advisor
信息安全分析师

Help developers assess security impact of their work and recommend threat modeling when appropriate. Use when developer is planning changes or asks about security. Respects autonomy and workflow while providing guidance.

2026-02-10
threats-and-countermeasures
信息安全分析师

Analyze IriusRisk-generated threats and countermeasures from JSON files. Use when user asks about threats, security issues, or wants to understand security findings. Read and explain findings, prioritize by risk, provide implementation guidance.

2026-02-10
ci-cd-verification
信息安全分析师

Orchestrate comprehensive CI/CD security reviews combining version comparison, control verification, risk analysis, and reporting. Use when running automated CI/CD pipeline security checks or when user requests full security assessment.

2026-02-10
compare-versions
信息安全分析师

Compare different states of a threat model to identify architectural and security changes. Use when reviewing pull requests for security impacts, detecting drift from approved baselines, or auditing historical changes. Returns structured diff for interpretation.

2026-02-10
countermeasure-verification
信息安全分析师

Verify that security controls (countermeasures) linked to issue tracker tasks are correctly implemented in code. Use when reviewing PRs that claim to implement specific security controls or validating documented controls match implementation.

2026-02-10
otm-validation-guidance
信息安全分析师

Detailed validation rules for OTM files. Use when validating trust zone IDs, component types, and filtering deprecated components. Critical for preventing import failures.

2026-02-10