Install
$ agentstack add skill-0xrafasec-ai-workflow-security ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Create the threat model. Argument: $ARGUMENTS
Context Gathering
Before interviewing, understand the system's security surface:
- Check for existing docs:
- Read
docs/THREAT_MODEL.md— if revising, don't start from scratch - Read
docs/ARCHITECTURE.mdfor system structure and trust boundaries - Read
CLAUDE.md,README.md
- Explore the codebase for security-relevant patterns:
- Look for auth middleware, JWT handling, session management
- Check for input validation patterns (or lack thereof)
- Look for database queries (raw SQL vs ORM/parameterized)
- Check for secrets management (env vars, config files, hardcoded values)
- Check for exposed endpoints (route definitions, API handlers)
- Read
docker-compose.ymlor deployment config for service exposure - Summarize what you found to the user — "Here's what I see from a security perspective: ..."
Interview
Use AskUserQuestion to understand the security landscape. Adapt based on what the codebase reveals.
- Trust boundaries — What is trusted? What is untrusted? Where are the boundaries?
- Authentication — How do users/agents/services prove identity? What mechanisms exist today?
- Authorization — Who can do what? How are permissions modeled?
- Sensitive data — What data is sensitive? Credentials, PII, financial? Where does it live? How is it protected at rest and in transit?
- Attack surface — What is exposed to the internet? To local users? To other services? What inputs does the system accept?
- Threat actors — Who would attack this? Script kiddies, insiders, nation states? What are their capabilities?
- Compliance — Any regulatory requirements? SOC2, GDPR, HIPAA, PCI?
- Existing security measures — What's already in place? What's missing?
For inherited projects: "I see you're using X for auth — is that intentional or legacy? I notice Y has no input validation — is that a known gap?"
Write
Write to docs/THREAT_MODEL.md:
# Threat Model
**Version:** [version]
**Date:** [date]
## Trust Assumptions
[What is the trust model? What is trusted, what is untrusted? Include a Mermaid diagram of the trust hierarchy.]
## Security Properties
[Non-negotiable security invariants. Things that must always hold.]
- [Property 1]
- [Property 2]
## Attack Surface
| Surface | Exposure | Controls |
|---------|----------|----------|
| [surface] | [who can reach it] | [what protects it] |
## Threats
### [Threat Category 1: e.g., Agent Impersonation]
| # | Attack | Impact | Likelihood | Defense |
|---|--------|--------|------------|---------|
| 1 | [attack description] | [what happens] | [Low/Med/High] | [how it's prevented] |
### [Threat Category 2]
...
## Sensitive Data Inventory
| Data | Classification | At Rest | In Transit | Access Control |
|------|---------------|---------|------------|----------------|
| [data type] | [level] | [protection] | [protection] | [who can access] |
## Security Controls
### Implemented
- [Control 1 — what it protects against]
### Required (not yet implemented)
- [Control 1 — what it would protect against, priority]
## Compliance Requirements
[If applicable. Regulatory frameworks, what they require, current status.]
After Writing
- Present the document to the user for review. Iterate until they're satisfied.
- Suggest next steps based on what exists:
- No architecture doc? → "Define system structure with
/architecture" - No TDD? → "Define testing and dev workflow with
/tdd" - Ready to build? → "Create feature specs with
/spec, then/roadmap"
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: 0xrafasec
- Source: 0xrafasec/ai-workflow
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.