All skills
wshobson avatar

/security-requirement-extraction

@be57c0b
by Seth Hobsonwshobson/agents40k stars
4,281

Derive security requirements from threat models and business context. Use when translating threats into actionable requirements, creating security user stories, or building security test cases.

Use this Skill: https://skilld.dev/gh/wshobson/agents/security-requirement-extraction

This session only. Nothing lands on disk.

SKILL.md

≈57 tokens always: the name and description. ≈571 when used: this file. ≈5.5k more on demand in 1 file.

Security Requirement Extraction

Transform threat analysis into actionable security requirements.

When to Use This Skill

  • Converting threat models to requirements
  • Writing security user stories
  • Creating security test cases
  • Building security acceptance criteria
  • Compliance requirement mapping
  • Security architecture documentation

Core Concepts

1. Requirement Categories

Business Requirements → Security Requirements → Technical Controls
         ↓                       ↓                      ↓
  "Protect customer    "Encrypt PII at rest"   "AES-256 encryption
   data"                                        with KMS key rotation"

2. Security Requirement Types

Type Focus Example
Functional What system must do "System must authenticate users"
Non-functional How system must perform "Authentication must complete in <2s"
Constraint Limitations imposed "Must use approved crypto libraries"

3. Requirement Attributes

Attribute Description
Traceability Links to threats/compliance
Testability Can be verified
Priority Business importance
Risk Level Impact if not met

Templates and detailed worked examples

Full template library lives in references/details.md. Read that file when you need concrete templates for this skill.

Best Practices

Do's

  • Trace to threats - Every requirement should map to threats
  • Be specific - Vague requirements can't be tested
  • Include acceptance criteria - Define "done"
  • Consider compliance - Map to frameworks early
  • Review regularly - Requirements evolve with threats

Don'ts

  • Don't be generic - "Be secure" is not a requirement
  • Don't skip rationale - Explain why it matters
  • Don't ignore priorities - Not all requirements are equal
  • Don't forget testability - If you can't test it, you can't verify it
  • Don't work in isolation - Involve stakeholders

Source: SKILL.md on GitHub

No alerts16d5 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The skill provides templates and Python logic designed to extract security requirements from threat models and map them to compliance frameworks. No security risks or malicious behaviors were detected.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer6mo

    1/1 file flagged

  • ZeroLeaks5mo

    1 finding · Score: 82/100

Signed by skilld at be57c0b. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 3 days ago.

Activeupdated 4 months ago
  • Security
  • threat-modeling
  • requirements
  • compliance
  • user-stories
  • test-cases
  • security-architecture
  • acceptance-criteria

README badge

README badge for wshobson/agents/security-requirement-extraction

Extracts security requirements from threat models and business context, mapping threats to functional, non-functional, and constraint requirements with traceability and testability attributes. Use this skill when translating threat analysis into security user stories, test cases, or acceptance criteria for compliance frameworks.

Generated from the current SKILL.md.

Does this skill help convert threat models into security requirements?
Yes. The skill provides templates and structured approaches to map threats and business context into actionable security requirements with traceability, testability, and priority attributes.
What types of security requirements does this skill cover?
The skill addresses functional requirements (what the system must do), non-functional requirements (performance constraints), and constraints (approved libraries or standards).
Can I use this skill to create security test cases or acceptance criteria?
Yes. The skill is designed for writing security user stories, test cases, and acceptance criteria, with emphasis on testability and compliance mapping.
Does this skill include templates?
Yes. A full template library is available in the references/details.md file bundled with the skill.

Generated from the current SKILL.md. These answers refresh after source changes.