Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIMuseMuseDotsDots+22 more

    security requirements extraction

    1

    Translates threat models, risks, and compliance gaps into testable security requirements and Jira-ready user stories.

    $15

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    Security scanned
    security requirements extraction

    security requirements extraction

    Example session with this skill installed

    Extract security requirements from this threat: 'Attacker intercepts PII in transit between the web frontend and the API.' Target audience is the engineering team using a Jira backlog format.

    • Read your context and instructions
    • Compiled the security requirements extraction
    • Generated the data export

    I have analyzed the threat regarding PII interception and derived the following engineering requirements. Each item includes specific acceptance criteria and validation methods suitable for your Jira backlog.

    Security Requirement Catalogue: Data in Transit Protection

    IDRequirement StatementTypeSource DriverRationaleAcceptance CriteriaValidation Method
    SEC-001Implement TLS 1.3 for all traffic between Frontend and API.FunctionalInterception of PIIPrevents man-in-the-middle (MITM) attacks and data exposure.Connections using TLS < 1.2 are rejected. Cipher suites are limited to AEAD.Automated scan using sslyze or nmap --script ssl-enum-ciphers.
    SEC-002Enforce HSTS (HTTP Strict Transport Security) headers.ConstraintInterception of PIIEnsures browsers only communicate over HTTPS, preventing protocol downgrade.Strict-Transport-Security header is present with max-age of at least 31536000.Browser console inspection and header analysis tools.
    SEC-003Use Certificate Pinning or CAA records to restrict CA issuance.AssuranceInterception of PIIMitigates risk of fraudulent certificate issuance.DNS records include valid CAA entries for authorized CAs.DNS lookup for Type 257 (CAA) records.

    Next steps

    1. Review the cipher suite whitelist with the infrastructure team.
    2. Confirm if the legacy mobile clients support TLS 1.3 or if a 1.2 fallback is required.
    3. Export these rows to your Jira CSV importer.

    security-requirements-extraction.csv

    CSV · data export

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Convert threat models into actionable engineering backlogs.Generate measurable acceptance criteria for security user stories.Create traceability links between risks and technical controls.Build security test cases from architectural design notes.

    About this skill

    The problem

    Security goals often stall because they are stated as vague aspirations rather than actionable engineering tasks. Developers and architects struggle to translate high-level threat models or compliance mandates into specific, testable requirements that fit into a sprint.

    What it does

    • Converts threat models and risk scenarios into granular, traceable security requirements.
    • Generates security-focused user stories with explicit acceptance criteria for engineering teams.
    • Builds validation methods and test cases directly from architectural constraints or control gaps.
    • Maps requirements to supplied compliance frameworks or internal policies without inventing data.
    • Classifies requirements by type: functional, non-functional, process, or assurance.

    Why this beats prompting it yourself

    Generic prompts often return broad security advice like "use encryption." This skill enforces a strict schema that includes rationale, evidence requirements, and measurable validation methods for every entry. It prevents the hallucination of framework clauses and ensures every requirement is tied to a specific source driver.

    Use cases

    • Transforming a STRIDE threat model into a prioritized product backlog.
    • Deriving acceptance criteria for a new identity service based on internal auth policies.
    • Generating a security assurance checklist for a third-party vendor integration.
    • Creating testable security stories for a cloud migration project.

    Known limitations

    Does not provide offensive exploit instructions or bypass methods. Requires the user to provide the specific frameworks or policies for mapping as it will not invent external control text.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 1 month ago

    • Passed all security checks, Safe to install

    Listed1 month ago

    What's inside

    Frequently Asked Questions