awesome-claude-code-security-compliance-suite
Security & compliance skill suite providing OWASP scanning, CVE detection, GDPR/SOC2 audits, threat modeling, and incident response workflows for AI coding agents
Install
npx skills add https://github.com/reason-machines/security-skills --skill awesome-claude-code-security-compliance-suiteš Security & Compliance Skills Suite
Skill by ara.so ā Security Skills collection.
A comprehensive security and compliance skill suite derived from hesreallyhim/awesome-claude-code, providing specialized commands and workflows for security audits, vulnerability management, GDPR/SOC2/ISO27001 compliance, and incident response.
What This Project Does
This skill suite provides 10 specialized security commands and 5 multi-step compliance workflows with structured output UI for:
- Vulnerability Scanning: OWASP Top-10 analysis, dependency CVE detection
- Compliance Auditing: GDPR, SOC2, ISO27001 gap analysis
- Security Operations: Threat modeling, penetration testing, IAM audits
- Incident Response: Breach response playbooks and investigation workflows
- Policy Generation: Privacy policies, security documentation
All commands use consistent structured output with progress tracking, findings tables, and prioritized action plans.
Installation
Quick Install (Local Skills Directory)
# Create Claude skills directory if it doesn't exist
mkdir -p ~/.claude/skills
# Clone the skill suite
git clone https://github.com/sparkfinderoven/r01-hesreallyhim-awesome-claude-code-security.git \
~/.claude/skills/awesome-claude-code-security
# Activate in Claude Code session
# In your IDE with Claude Code, run:
/read ~/.claude/skills/awesome-claude-code-security/SKILL.md
Manual Installation
# Clone the repository
git clone https://github.com/sparkfinderoven/r01-hesreallyhim-awesome-claude-code-security.git
# Navigate to project directory
cd r01-hesreallyhim-awesome-claude-code-security
# Read the skill documentation
cat SKILL.md
Verification
Verify installation by checking available commands:
# List all security commands
ls -la ~/.claude/skills/awesome-claude-code-security/
# Expected output:
# - SKILL.md (this file)
# - README.md (documentation)
# - commands/ (individual command definitions)
# - workflows/ (multi-step workflow definitions)
Core Commands
1. OWASP Top-10 Security Scan
Scans code for OWASP Top-10 vulnerabilities with CVSS scores and remediation guidance.
/owasp-scan <target_directory>
# Options
/owasp-scan src/ --format json
/owasp-scan . --severity critical,high
/owasp-scan api/ --output report.md
Example Output Structure:
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
ā OWASP Security Scan ā ./src/api ā
ā āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā£
ā Files scanned ā 47 ā
ā OWASP checks ā 14 ā
ā Findings ā 8 issues ā
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
FINDINGS (severity: desc)
āāāāāāāā¬āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā¬āāāāāāāāāāā¬āāāāāāāāāāāāāāā
ā Sev ā Vulnerability ā CVSS ā File ā
āāāāāāāā¼āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā¼āāāāāāāāāāā¼āāāāāāāāāāāāāāā¤
ā š“ ā SQL Injection ā 9.8 ā users.js:42 ā
ā š“ ā JWT None Algorithm ā 9.1 ā auth.js:18 ā
ā š ā CORS Misconfiguration ā 6.5 ā server.js:12 ā
āāāāāāāā“āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā“āāāāāāāāāāā“āāāāāāāāāāāāāāā
REMEDIATION
⢠SQL Injection: Use parameterized queries or ORM
⢠JWT None: Validate algorithm in token verification
⢠CORS: Restrict origins to known domains
2. Dependency CVE Scanner
Scans project dependencies for known CVEs with exploitability scores.
/dep-cve
# Options
/dep-cve --scope production
/dep-cve --output json > cve-report.json
/dep-cve --min-cvss 7.0
/dep-cve --show-paths
Example for Node.js project:
# Scans package.json and package-lock.json
/dep-cve --scope full
# Output includes:
# - CVE IDs with CVSS scores
# - Affected package versions
# - Upgrade paths
# - Exploitability assessment
Expected Output:
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
ā CVE Dependency Scan ā
ā āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā£
ā Dependencies checked ā 234 ā
ā CVEs found ā 12 ā
ā Critical ā 3 ā
ā High ā 5 ā
ā Medium ā 4 ā
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
āāāāāāāāāāāāāāā¬āāāāāāāāāāā¬āāāāāāāāāāāāāā¬āāāāāāāāāāāāāāā¬āāāāāāāāāāāāāā
ā Package ā CVE ā CVSS ā Installed ā Fixed In ā
āāāāāāāāāāāāāāā¼āāāāāāāāāāā¼āāāāāāāāāāāāāā¼āāāāāāāāāāāāāāā¼āāāāāāāāāāāāāā¤
ā lodash ā CVE-2021 ā 9.8 š“ ā 4.17.15 ā 4.17.21 ā
ā axios ā CVE-2022 ā 8.1 š“ ā 0.21.0 ā 0.21.4 ā
ā express ā CVE-2022 ā 7.5 š ā 4.17.1 ā 4.18.2 ā
āāāāāāāāāāāāāāā“āāāāāāāāāāā“āāāāāāāāāāāāāā“āāāāāāāāāāāāāāā“āāāāāāāāāāāāāā
UPGRADE COMMANDS
npm install lodash@4.17.21
npm install axios@0.21.4
npm install express@4.18.2
3. GDPR Compliance Audit
Maps data flows, identifies consent gaps, and generates DPA checklist.
/gdpr-audit <application_path>
# Options
/gdpr-audit . --data-map
/gdpr-audit src/ --consent-analysis
/gdpr-audit . --full-report --output gdpr-audit.pdf
Example Analysis:
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
ā GDPR Compliance Audit ā
ā āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā£
ā Data flows mapped ā 24 ā
ā Personal data types ā 8 ā
ā Consent gaps ā 5 ā
ā DPA requirements ā 12/15 met ā
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
DATA FLOW MAP
User Registration ā Database (PII: email, name, phone)
ā³ Consent: ā Missing explicit opt-in
ā³ Retention: ā No deletion policy defined
ā³ Encryption: ā AES-256 at rest
Analytics Pipeline ā Third-party (IP address, user agent)
ā³ Consent: ā No cookie banner
ā³ DPA: ā No Data Processing Agreement on file
COMPLIANCE GAPS
š“ Critical:
⢠No cookie consent mechanism implemented
⢠Missing data retention policies in privacy policy
⢠No user data deletion endpoint
š High:
⢠DPA missing for analytics provider
⢠DSAR (data subject access request) workflow undefined
4. SOC2 Readiness Assessment
Performs gap analysis across all 5 Trust Service Criteria.
/soc2-readiness
# Options
/soc2-readiness --criteria security,availability
/soc2-readiness --type type2
/soc2-readiness --output xlsx
Example Output:
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
ā SOC 2 Type II Readiness Assessment ā
ā āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā£
ā Security ā 65% ready ā
ā Availability ā 90% ready ā
ā Confidentiality ā 45% ready ā
ā Processing Integrity ā 70% ready ā
ā Privacy ā 50% ready ā
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
SECURITY GAPS
ā CC6.1: No background checks policy
ā CC6.6: Missing logical access reviews (quarterly)
ā CC7.2: Incomplete system monitoring
AVAILABILITY GAPS
ā A1.2: RTO/RPO not documented in DR plan
REMEDIATION TIMELINE
Quick Wins (1-2 weeks):
⢠Document RTO/RPO targets
⢠Implement access review schedule
Medium-term (1-3 months):
⢠Establish background check policy
⢠Deploy SIEM for continuous monitoring
Strategic (3-6 months):
⢠Conduct third-party penetration test
⢠Implement data classification framework
5. Threat Modeling (STRIDE)
Generates STRIDE threat model for architecture diagrams.
/threat-model <architecture_file>
# Options
/threat-model architecture.png --framework stride
/threat-model system-design.md --risk-matrix
/threat-model . --auto-discover
Example for Web Application:
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
ā STRIDE Threat Model ā
ā āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā£
ā Components analyzed ā 8 ā
ā Data flows ā 12 ā
ā Threats identified ā 18 ā
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
ARCHITECTURE COMPONENTS
⢠Web Application (React SPA)
⢠API Gateway (nginx)
⢠Backend API (Node.js/Express)
⢠Database (PostgreSQL)
⢠Auth Service (OAuth2)
⢠External Payment Gateway
THREAT ANALYSIS (STRIDE)
[S]poofing
š“ API Gateway: No mutual TLS for backend communication
Impact: High | Likelihood: Medium
Mitigation: Implement mTLS between gateway and API
[T]ampering
š Database: SQL injection possible via user input
Impact: Critical | Likelihood: Low
Mitigation: Use parameterized queries
[R]epudiation
š” API: Insufficient audit logging for sensitive operations
Impact: Medium | Likelihood: Medium
Mitigation: Implement comprehensive audit trail
[I]nformation Disclosure
š“ Payment Flow: PCI data logged in application logs
Impact: Critical | Likelihood: Medium
Mitigation: Implement PCI-compliant logging filters
[D]enial of Service
š API: No rate limiting on public endpoints
Impact: High | Likelihood: High
Mitigation: Implement rate limiting middleware
[E]levation of Privilege
š“ Auth: JWT lacks role claims validation
Impact: Critical | Likelihood: Medium
Mitigation: Add RBAC middleware with role enforcement
RISK MATRIX
Impact ā
Likelihood ā Low Medium High Critical
āāāāāāāāāāāā¼āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
High ā DoS
Medium ā Repud. Spoof InfoDisc, EoP
Low ā Tamper
6. Penetration Test Report Generator
Structures penetration test findings with executive summary and remediation.
/pentest-report <findings_file>
# Options
/pentest-report findings.json --template executive
/pentest-report scan-results/ --format pdf
/pentest-report . --cvss-threshold 7.0
Example Report Structure:
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
ā Penetration Test Report ā
ā Target: api.example.com ā
ā Date: 2024-01-15 ā
ā āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā£
ā Critical findings ā 4 ā
ā High findings ā 7 ā
ā Medium findings ā 12 ā
ā Low/Info ā 8 ā
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
EXECUTIVE SUMMARY
The penetration test identified 31 findings across the web application
and API infrastructure. 4 critical vulnerabilities require immediate
remediation, including SQL injection and authentication bypass issues.
CRITICAL FINDINGS
1. SQL Injection in User Search (CVSS 9.8)
Location: /api/v1/users/search?q=
Description:
User-supplied input in the 'q' parameter is directly concatenated
into SQL query without sanitization.
Proof of Concept:
GET /api/v1/users/search?q=' OR '1'='1
Remediation:
⢠Implement parameterized queries
⢠Add input validation and sanitization
⢠Deploy WAF rules to detect SQL injection patterns
Timeline: Immediate (< 48 hours)
2. Authentication Bypass via JWT None Algorithm (CVSS 9.1)
Location: /api/v1/auth/verify
Description:
JWT library accepts 'none' algorithm, allowing unsigned tokens.
Proof of Concept:
eyJhbGciOiJub25lIiwidHlwIjoiSldUIn0.eyJ1c2VyIjoiYWRtaW4ifQ.
Remediation:
⢠Explicitly reject 'none' algorithm in JWT verification
⢠Implement algorithm whitelist
⢠Add token signature validation tests
Timeline: Immediate (< 48 hours)
REMEDIATION ROADMAP
Immediate (< 48 hours):
ā Fix SQL injection vulnerabilities
ā Patch JWT authentication bypass
ā Disable debug endpoints in production
Short-term (1-2 weeks):
ā Implement rate limiting
ā Add CSRF protection
ā Deploy Web Application Firewall
Medium-term (1 month):
ā Conduct security code review
ā Implement security headers (CSP, HSTS)
ā Add automated security scanning to CI/CD
7. Secret Detection (Pre-commit Hook)
Configures pre-commit hooks for secret and credential detection.
/secret-detect init
# Options
/secret-detect scan <directory>
/secret-detect --entropy-threshold 4.5
/secret-detect --add-patterns custom-patterns.json
Example Configuration:
# Initialize secret detection
/secret-detect init
# Creates .pre-commit-config.yaml
Generated .pre-commit-config.yaml:
repos:
- repo: https://github.com/Yelp/detect-secrets
rev: v1.4.0
hooks:
- id: detect-secrets
args:
- '--baseline'
- '.secrets.baseline'
- '--exclude-files'
- 'package-lock.json|.*\.min\.js'
- repo: https://github.com/gitleaks/gitleaks
rev: v8.18.0
hooks:
- id: gitleaks
args:
- '--verbose'
- '--redact'
# Custom entropy scanning
- repo: local
hooks:
- id: high-entropy-strings
name: Detect high-entropy strings
entry: python scripts/entropy-scan.py
language: python
args: ['--threshold', '4.5']
Scan Example:
/secret-detect scan src/
# Output:
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
ā Secret Detection Scan ā
ā āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā£
ā Files scanned ā 156 ā
ā Secrets detected ā 8 ā
ā High entropy strings ā 3 ā
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
DETECTED SECRETS
āāāāāāāāāāāāāāāāāāāāāāā¬āāāāāāāāāāāāāāāāāāā¬āāāāāāāāāāāāāāāāāā
ā Type ā File ā Line ā
āāāāāāāāāāāāāāāāāāāāāāā¼āāāāāāāāāāāāāāāāāāā¼āāāāāāāāāāāāāāāāāā¤
ā AWS Access Key ā config.js ā 12 ā
ā Private Key ā certs/dev.key ā 1 ā
ā API Key (Generic) ā api-client.js ā 45 ā
ā High Entropy String ā utils.js ā 89 ā
āāāāāāāāāāāāāāāāāāāāāāā“āāāāāāāāāāāāāāāāāāā“āāāāāāāāāāāāāāāāāā
REMEDIATION
⢠Move secrets to environment variables
⢠Add affected files to .gitignore
⢠Rotate exposed credentials immediately
⢠Review git history with: git log -p <file>
8. IAM Least Privilege Audit
Audits IAM roles for over-permissions, stale access, and MFA gaps.
/iam-audit
# Options
/iam-audit --provider aws
/iam-audit --check-mfa
/iam-audit --stale-days 90
/iam-audit --output csv
Example AWS IAM Audit:
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
ā IAM Least Privilege Audit (AWS) ā
ā āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā£
ā Users analyzed ā 24 ā
ā Roles analyzed ā 18 ā
ā Over-permissioned ā 7 ā
ā Stale access (90d) ā 5 ā
ā Missing MFA ā 3 ā
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
OVER-PERMISSIONED ROLES
āāāāāāāāāāāāāāāāāāāā¬āāāāāāāāāāāāāāāāāā¬āāāāāāāāāāāāāāāāāāā
ā Role/User ā Issue ā Last Used ā
āāāāāāāāāāāāāāāāāāāā¼āāāāāāāāāāāāāāāāāā¼āāāāāāāāāāāāāāāāāāā¤
ā DevOps-Role ā Admin policy ā 2 days ago ā
ā DataScience-Role ā S3 Full Access ā 15 days ago ā
ā CI-Pipeline ā IAM permissions ā 1 day ago ā
āāāāāāāāāāāāāāāāāāāā“āāāāāāāāāāāāāāāāāā“āāāāāāāāāāāāāāāāāāā
RECOMMENDATIONS
DevOps-Role:
Current: AdministratorAccess
Recommended: Custom policy with specific permissions
Unused services: RDS, Lambda, DynamoDB
Suggested Policy:
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"ec2:*",
"s3:GetObject",
"s3:PutObject",
"cloudwatch:PutMetricData"
],
"Resource": "*"
}
]
}
STALE ACCESS (>90 days)
⢠jenkins-user (145 days) - Consider deactivating
⢠legacy-integration (234 days) - Remove
⢠contractor-temp (98 days) - Review and remove
MISSING MFA
š“ admin-user (console access)
š“ ops-team-lead (console access)
ā backup-operator (API only)
ACTION PLAN
Immediate:
ā Enable MFA for admin-user and ops-team-lead
ā Deactivate access for legacy-integration
Short-term:
ā Replace AdministratorAccess with scoped policies
ā Implement 90-day access review process
ā Add MFA enforcement policy
9. Security Incident Playbook
Generates security incident response playbook following NIST framework.
/incident-playbook <incident_type>
# Options
/incident-playbook data-breach
/incident-playbook ransomware
/incident-playbook ddos-attack
/incident-playbook --format pdf
Example Playbook:
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
ā Security Incident Playbook: Data Breach ā
ā āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā£
ā Framework: NIST SP 800-61 ā
ā Phases: 5 ā
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
PHASE 1: DETECTION & TRIAGE (0-1 hour)
Immediate Actions:
ā Confirm incident severity and scope
ā Notify Security Team Lead
ā Activate incident response team
ā Begin incident log (time, actions, findings)
Detection Checklist:
ā Review SIEM alerts and logs
ā Check data exfiltration indicators
ā Identify compromised systems/accounts
ā Determine data types affected
Key Questions:
⢠What data was accessed/exfiltrated?
⢠How many records affected?
⢠When did the breach occur?
⢠Is the breach ongoing?
PHASE 2: CONTAINMENT (1-4 hours)
Short-term Containment:
ā Isolate affected systems from network
ā Disable compromised user accounts
ā Block malicious IP addresses at firewall
ā Reset credentials for affected systems
ā Enable enhanced monitoring
Long-term Containment:
ā Apply security patches
ā Implement additional access controls
ā Deploy IDS/IPS rules
ā Segment network if not already done
Evidence Preservation:
ā Take disk/memory snapshots
ā Preserve logs (application, system, network)
ā Document all containment actions
ā Chain of custody for forensic evidence
PHASE 3: ERADICATION (4-24 hours)
ā Remove malware/backdoors from affected systems
ā Close vulnerability that enabled breach
ā Verify no persistence mechanisms remain
ā Conduct full system security scan
ā Review and update security configurations
Root Cause Analysis:
⢠Entry point identification
⢠Attack vector analysis
⢠Timeline reconstruction
⢠Identify control failures
PHASE 4: RECOVERY (1-7 days)
ā Restore systems from clean backups
ā Verify system integrity before reconnection
ā Gradually restore services (least critical first)
ā Enhanced monitoring for 30 days
ā User access verification
Validation:
ā Penetration testing of restored systems
ā Vulnerability scanning
ā Security control verification
PHASE 5: POST-INCIDENT (7-30 days)
Lessons Learned Meeting (within 48 hours):
⢠What happened?
⢠What was done well?
⢠What could be improved?
⢠What will we do differently?
Deliverables:
ā Incident report (technical)
ā Executive summary
ā Timeline of events
ā Financial impact assessment
ā Regulatory notification (if required)
Regulatory Obligations:
⢠GDPR: 72-hour notification to supervisory authority
⢠CCPA: Notification without unreasonable delay
⢠HIPAA: 60-day notification to affected individuals
⢠State breach notification laws (check jurisdictions)
Security Improvements:
ā Update incident response plan
ā Implement identified security controls
ā Conduct security awareness training
ā Schedule follow-up security assessment
CONTACTS
Security Team:
⢠Security Lead: ENV:SECURITY_LEAD_CONTACT
⢠On-Call SIEM: ENV:SIEM_ONCALL
⢠Forensics Team: ENV:FORENSICS_CONTACT
External:
⢠Legal Counsel: ENV:LEGAL_CONTACT
⢠PR/Communications: ENV:PR_CONTACT
⢠Cyber Insurance: ENV:INSURANCE_CONTACT
⢠Law Enforcement (FBI IC3): https://www.ic3.gov
Regulatory:
⢠GDPR DPA: ENV:DPA_CONTACT
⢠State Attorney General: ENV:STATE_AG_CONTACT
10. Privacy Policy Generator
Generates GDPR/CCPA-compliant privacy policy from data inventory.
/privacy-policy <data_inventory_file>
# Options
/privacy-policy inventory.json --jurisdiction eu,us,uk
/privacy-policy . --auto-discover
/privacy-policy data-map.yaml --format html
Example Data Inventory:
{
"personal_data": [
{
"type": "contact",
"fields": ["email", "name", "phone"],
"purpose": "user_account",
"retention": "account_lifetime",
"third_parties": []
},
{
"type": "analytics",
"fields": ["ip_address", "user_agent", "session_id"],
"purpose": "service_improvement",
"retention": "90_days",
"third_parties": ["Google Analytics"]
}
]
}
Generated Policy Excerpt:
# Privacy Policy
Last Updated: 2024-01-15
## 1. Information We Collect
### Contact Information
We collect your email address, name, and phone number when you:
- Create an account
- Contact customer support
- Subscribe to our newsletter
**Legal Basis (GDPR):** Contract performance, legitimate interest
**Retention:** Duration of account plus 30 days
### Analytics Data
We automatically collect:
- IP address
- Browser type and version
- Device information
- Pages visited and time spent
**Legal Basis (GDPR):** Legitimate interest (service improvement)
**Retention:** 90 days
## 2. How We Use Your Information
We use your information to:
- Provide and maintain our services
- Send account-related notifications
- Improve our products and services
- Comply with legal obligations
## 3. Third-Party Service Providers
We share your information with:
**Google Analytics**
- Purpose: Website analytics and usage patterns
- Data shared: IP address, user agent, page views
- Location: United States
- Privacy Policy: https://policies.google.com/privacy
- Data Processing Agreement: In place
## 4. Your Rights (GDPR)
You have the right to:
- **Access:** Request a copy of your personal data
- **Rectification:** Correct inaccurate data
- **Erasure:** Request deletion of your data
- **Restriction:** Limit processing of your data
- **Portability:** Receive your data in machine-readable format
- **Objection:** Object to processing based on legitimate interest
- **Withdraw Consent:** Where processing is based on consent
To exercise these rights, contact: ENV:PRIVACY_CONTACT_EMAIL
## 5. Your Rights (CCPA)
California residents have the right to:
- Know what personal information is collected
- Know whether personal information is sold or disclosed
- Say no to the sale of personal information
- Access your personal information
- Request deletion of personal information
- Equal service and price, even if you exercise your privacy rights
## 6. Data Security
We implement appropriate technical and organizational measures:
- Encryption in transit (TLS 1.3)
- Encryption at rest (AES-256)
- Access controls and authentication
- Regular security assessments
- Employee security training
## 7. International Data Transfers
Your data may be transferred to and processed in:
- United States (Standard Contractual Clauses)
- European Union (GDPR compliant)
We ensure appropriate safeguards are in place for all transfers.
## 8. Children's Privacy
Our services are not directed to individuals under 16. We do not
knowingly collect personal information from children.
## 9. Contact Information
Data Controller: [Company Name]
Email: ENV:PRIVACY_CONTACT_EMAIL
Address: [Company Address]
EU Representative: ENV:EU_REP_CONTACT
UK Representative: ENV:UK_REP_CONTACT
Supervisory Authority: [Relevant DPA]
Multi-Step Workflows
Workflow 1: Secure SDLC (Shift-Left Security)
End-to-end secure development lifecycle implementation.
/workflow:secure-sdlc <project_path>
# Options
/workflow:secure-sdlc . --phase all
/workflow:secure-sdlc src/ --skip-dast
Workflow Steps:
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
ā Secure SDLC Workflow ā
ā āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā£
ā 1. Threat Model ā³ In Progress ā
ā 2. SAST Scan ā Pending ā
ā 3. Dependency Check ā Pending ā
ā 4. DAST Scan ā Pending ā
ā 5. Penetration Test ā Pending ā
ā 6. Security Sign-off ā Pending ā
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
PHASE 1: THREAT MODELING
Running: /threat-model architecture.md
[Output from threat model command...]
PHASE 2: STATIC ANALYSIS
Running: /owasp-scan src/
[Output from OWASP scan...]
PHASE 3: DEPENDENCY CHECK
Running: /dep-cve --scope full
[Output from CVE scan...]
PHASE 4: DYNAMIC TESTING
Running DAST against staging environment...
[DAST results...]
PHASE 5: PENETRATION TEST
Generating penetration test checklist...
[Pentest scope and requirements...]
PHASE 6: SECURITY SIGN-OFF
Generating security release checklist...
RELEASE CRITERIA
ā All critical vulnerabilities resolved