Works with the AI tools you already use
security requirements extraction
Translates threat models, risks, and compliance gaps into testable security requirements and Jira-ready user stories.
$15
security requirements extraction
Example session with this skill installed
Extract security requirements from this threat: 'Attacker intercepts PII in transit between the web frontend and the API.' Target audience is the engineering team using a Jira backlog format.
- Read your context and instructions
- Compiled the security requirements extraction
- Generated the data export
I have analyzed the threat regarding PII interception and derived the following engineering requirements. Each item includes specific acceptance criteria and validation methods suitable for your Jira backlog.
Security Requirement Catalogue: Data in Transit Protection
| ID | Requirement Statement | Type | Source Driver | Rationale | Acceptance Criteria | Validation Method |
|---|---|---|---|---|---|---|
| SEC-001 | Implement TLS 1.3 for all traffic between Frontend and API. | Functional | Interception of PII | Prevents man-in-the-middle (MITM) attacks and data exposure. | Connections using TLS < 1.2 are rejected. Cipher suites are limited to AEAD. | Automated scan using sslyze or nmap --script ssl-enum-ciphers. |
| SEC-002 | Enforce HSTS (HTTP Strict Transport Security) headers. | Constraint | Interception of PII | Ensures browsers only communicate over HTTPS, preventing protocol downgrade. | Strict-Transport-Security header is present with max-age of at least 31536000. | Browser console inspection and header analysis tools. |
| SEC-003 | Use Certificate Pinning or CAA records to restrict CA issuance. | Assurance | Interception of PII | Mitigates risk of fraudulent certificate issuance. | DNS records include valid CAA entries for authorized CAs. | DNS lookup for Type 257 (CAA) records. |
Next steps
- Review the cipher suite whitelist with the infrastructure team.
- Confirm if the legacy mobile clients support TLS 1.3 or if a 1.2 fallback is required.
- Export these rows to your Jira CSV importer.
security-requirements-extraction.csv
CSV · data export
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
The problem
Security goals often stall because they are stated as vague aspirations rather than actionable engineering tasks. Developers and architects struggle to translate high-level threat models or compliance mandates into specific, testable requirements that fit into a sprint.
What it does
- Converts threat models and risk scenarios into granular, traceable security requirements.
- Generates security-focused user stories with explicit acceptance criteria for engineering teams.
- Builds validation methods and test cases directly from architectural constraints or control gaps.
- Maps requirements to supplied compliance frameworks or internal policies without inventing data.
- Classifies requirements by type: functional, non-functional, process, or assurance.
Why this beats prompting it yourself
Generic prompts often return broad security advice like "use encryption." This skill enforces a strict schema that includes rationale, evidence requirements, and measurable validation methods for every entry. It prevents the hallucination of framework clauses and ensures every requirement is tied to a specific source driver.
Use cases
- Transforming a STRIDE threat model into a prioritized product backlog.
- Deriving acceptance criteria for a new identity service based on internal auth policies.
- Generating a security assurance checklist for a third-party vendor integration.
- Creating testable security stories for a cloud migration project.
Known limitations
Does not provide offensive exploit instructions or bypass methods. Requires the user to provide the specific frameworks or policies for mapping as it will not invent external control text.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 1 month ago
- Passed all security checks, Safe to install