소개
This skill bridges the gap between high-level threat identification and technical implementation by deriving structured security requirements from business context and threat models. By utilizing frameworks like STRIDE, it maps potential risks to specific security domains—such as authentication, data protection, and audit logging—to generate developer-ready artifacts. It is an essential tool for teams adopting a 'secure-by-design' approach, providing automated generation of security user stories, acceptance criteria, and traceability matrices to ensure compliance with standards like OWASP, GDPR, and HIPAA.