CtrlK
BlogDocsLog inGet started
Tessl Logo

security-architecture

Security architecture design — threat modeling, zero trust, identity, encryption, compliance. Use when the user asks to 'design security architecture', 'model threats', 'implement zero trust', 'design IAM', 'plan encryption strategy', 'map compliance requirements', or mentions STRIDE, OWASP, OAuth, RBAC, SOC2, ISO27001, PCI-DSS. [EXPLICIT]

SKILL.md
Quality
Evals
Security

Security Architecture: Threat Modeling, Identity & Compliance Design

Generic, brand-neutral engineering capability; deep, sourced playbooks live in references/ and knowledge/. [DOC]

Generic, brand-neutral engineering capability; sourced playbooks in references//knowledge/. [DOC]

TL;DR

Security architecture defines how systems protect data, verify identity, enforce access, and maintain compliance across the entire technology stack. The skill produces comprehensive security designs covering threat modeling, zero trust implementation, identity management, data protection, application security pipelines, and compliance mapping [EXPLICIT]

When to Use

  • Designing security architecture for new systems or major platform changes
  • Conducting threat modeling for applications, APIs, or infrastructure
  • Implementing zero trust architecture
  • Designing identity and access management systems
  • Planning encryption and data protection strategies
  • Mapping compliance requirements to technical controls

When NOT to Use

  • CI/CD pipeline security (SAST/DAST integration only) — use devsecops-architecture
  • Infrastructure provisioning and network design — use infrastructure-architecture
  • Application code patterns and module design — use software-architecture
  • Penetration testing execution — requires specialized security team

Sub-capabilities (resource map)

Deep, evidence-tagged playbooks — open the one the task needs (ICM Layer 3, on-demand). [INFERENCE]

Reference
references/full-playbook.md
references/knowledge-graph.mmd
references/security-frameworks.md
references/state-of-the-art.md

Procedure

  1. Resolve the sub-capability; open the matching references/ playbook. [EXPLICIT]
  2. Apply its decision tables; pick the strategy explicitly. [EXPLICIT]
  3. Validate against the Quality Criteria and tag every claim. [EXPLICIT]

Quality Criteria

  • Sub-capability resolved to one playbook. [INFERENCE]
  • Claims evidence-tagged. [EXPLICIT]

Contract

  • Aceptación: capability resolved to its reference playbook, applied, validated, evidence-tagged. [EXPLICIT]
  • Límites: · Does not perform penetration testing or vulnerability exploitation · Does not replace legal counsel for regulatory interpretation · Threat models require periodic refresh as syst. [EXPLICIT]
  • Casos borde: Greenfield System: Design security from day one. Embed threat modeling in architecture review. Choose IdP and encryption strategy before first deployment. [EXPLICIT]
  • Supuestos: · System has defined data flows and component boundaries (or they can be established) · Organization has identified applicable regulatory frameworks · Security tooling budget is av. [SUPUESTO]
  • Trade-off: Decision Enables Constrains When to Use --- --- --- --- Zero trust everywhere Strong posture, lateral movement prevention Implementation complexity, latency o. [EXPLICIT]

Packet

Capas del packet, cargables bajo demanda (disciplina ICM: una capa por vez, nunca todas juntas): references/ guías de profundidad (cargar UNA por etapa) · knowledge/ cuerpo de conocimiento · prompts/ prompts listos · examples/ salida de ejemplo · agents/ subagentes del packet · assets/ recursos estáticos.

Repository
JaviMontano/claude-plugins
Last updated
First committed

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.