From security-scanning
Derive security requirements from threat models and business context. Use when translating threats into actionable requirements, creating security user stories, or building security test cases.
How this skill is triggered — by the user, by Claude, or both
Slash command
/security-scanning:security-requirement-extractionThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
Transform threat analysis into actionable security requirements.
Transform threat analysis into actionable security requirements.
Business Requirements → Security Requirements → Technical Controls
↓ ↓ ↓
"Protect customer "Encrypt PII at rest" "AES-256 encryption
data" with KMS key rotation"
| Type | Focus | Example |
|---|---|---|
| Functional | What system must do | "System must authenticate users" |
| Non-functional | How system must perform | "Authentication must complete in <2s" |
| Constraint | Limitations imposed | "Must use approved crypto libraries" |
| Attribute | Description |
|---|---|
| Traceability | Links to threats/compliance |
| Testability | Can be verified |
| Priority | Business importance |
| Risk Level | Impact if not met |
Full template library lives in references/details.md. Read that file when you need concrete templates for this skill.
npx claudepluginhub yo-steven/agents-exploration-20260523 --plugin security-scanningGuides test-driven development for Django applications using pytest-django, factory_boy, and Django REST Framework. Covers red-green-refactor workflow, conftest fixtures, and coverage reporting.