Threat modeling, compliance, and secure by design architecture
Scanned 10/6/2026
npx -y skills add DongDuong2001/pudo-code-system --skill security --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Security?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/dongduong2001-security)More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.
---
name: security-plan
description: Threat modeling, compliance, and secure by design architecture
---
# Security Planning Skill
This skill is focused on ensuring systems are resilient against attacks and inherently protect user data.
## When to use this skill
- When performing Threat Modeling (STRIDE) for new features.
- When planning Authentication, Authorization, and Session Management.
- When adhering to compliance requirements (GDPR, HIPAA, SOC2).
## Guidelines
- **Principle of Least Privilege:** Services and users should only have the bare minimum access permissions they need.
- **Defense in Depth:** Do not rely on a single defensive mechanism. Validate inputs at the client, the API edge, and the database boundary.
- **Secret Management:** Never hardcode secrets. Plan to use KMS, HashiCorp Vault, or environment-injected managed identities.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!