Loading...
Loading...
For authorized security review of code, auth, or APIs you control, model the attacker, map the attack surface, and report only findings with a reproducible exploit path and verified mitigation.
npx skill4agent add tjboudreaux/cc-thinking-skills thinking-red-teamTarget/scope: <in | out | goal | authorization>
Threat model: <actors, access, goals>
Attack surface: <entry points + trust boundaries>
Findings (only complete paths):
- Title | Severity
Entry: <endpoint/param/file>
Steps: <1..n>
Impact: <realized effect>
Bypass attempts: <control → result>
Mitigation: <minimal fix>
Re-test: <how to confirm closed>
Summary: <kept count; dropped speculative count>