# 007

> Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.

- **Type:** Skill
- **Install:** `agentstack add skill-newmindsgroup-ai-agent-skills-library-007`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [newmindsgroup](https://agentstack.voostack.com/s/newmindsgroup)
- **Installs:** 0
- **Category:** [Agent Skills](https://agentstack.voostack.com/c/agent-skills)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [newmindsgroup](https://github.com/newmindsgroup)
- **Source:** https://github.com/newmindsgroup/ai-agent-skills-library/tree/main/dist/skills/007
- **Website:** https://github.com/newmindsgroup/ai-agent-skills-library

## Install

```sh
agentstack add skill-newmindsgroup-ai-agent-skills-library-007
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# 007 — Licenca para Auditar

Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.

## When to Use
- The request matches the skill description: Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.
- The task needs the implementation patterns, examples, validation checks, or edge cases listed in the topic map.
- The work would benefit from the complete guidance preserved in `references/full-guidance.md`.

## Core Workflow
1. Confirm the request matches this skill's trigger, scope, and risk profile.
2. Use the topic map to identify the relevant pattern, checklist, or example before writing detailed guidance or code.
3. Load `references/full-guidance.md` when implementation details, examples, anti-patterns, validation checks, or edge cases are needed.
4. Apply only the relevant guidance instead of loading or repeating the entire reference by default.
5. Verify the result against any validation checks, limitations, security notes, or platform constraints in the reference.

## Topic Map
- Overview
- When to Use This Skill
- Do Not Use This Skill When
- How It Works
- 007 — Licenca Para Auditar
- Modos Operacionais
- Modo 1: `Audit` (Padrao)
- Modo 2: `Threat-Model`
- Modo 3: `Approve`
- Modo 4: `Block`
- Modo 5: `Monitor`
- Modo 6: `Incident`
- Processo De Analise — 6 Fases
- Fase 1: Mapeamento Da Superficie De Ataque
- Fase 2: Threat Modeling (Stride + Pasta)
- Fase 3: Checklist Tecnico De Seguranca
- Fase 4: Red Team Mental (Ataque Realista)
- Fase 5: Blue Team (Defesa E Hardening)

## Reference Map
- `references/full-guidance.md` preserves the complete original guidance, including examples and detailed edge cases.

## Limitations
- Use this skill only when the task clearly matches the scope described above.
- Do not treat the output as a substitute for environment-specific validation, testing, or expert review.
- Stop and ask for clarification if required inputs, permissions, safety boundaries, or success criteria are missing.

## Progressive Loading
Keep this `SKILL.md` as the compact routing and workflow entrypoint. Load the reference file only when the user task requires the deeper implementation material.

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [newmindsgroup](https://github.com/newmindsgroup)
- **Source:** [newmindsgroup/ai-agent-skills-library](https://github.com/newmindsgroup/ai-agent-skills-library)
- **License:** MIT
- **Homepage:** https://github.com/newmindsgroup/ai-agent-skills-library

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-newmindsgroup-ai-agent-skills-library-007
- Seller: https://agentstack.voostack.com/s/newmindsgroup
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
