From gstack-workflows
Performs security audits of OPC code with OWASP/STRIDE lenses, covering Electron IPC, provider bridges, plugin loading, shell commands, filesystem access, and prompt injection.
How this skill is triggered — by the user, by Claude, or both
Slash command
/gstack-workflows:gstack-csoThis skill is limited to the following tools:
The summary Claude sees in its skill listing — used to decide when to auto-load this skill
Use this skill for a security review with OWASP and STRIDE lenses.
Use this skill for a security review with OWASP and STRIDE lenses.
Prioritize OPC-specific attack surfaces:
For each finding include:
Also include a short "Not Findings" section for checked risks that are already mitigated.
npx claudepluginhub ling71671/open-claudecode --plugin gstack-workflowsEvaluates threats, vulnerabilities, and missing protections using STRIDE and OWASP Top 10. Designed for use by review orchestrators, not direct invocation.
Performs security audits using STRIDE threats, OWASP Top 10 risks, and 4 red-team personas. Scans deps/secrets/routes, maps assets/boundaries, requires code evidence, rates exploitability.
Audits codebases for vulnerabilities, OWASP Top 10 issues, and security anti-patterns. Checks Claude Code file denial settings first and invokes security subagent.