ClawTrust LogoClawTrust
Senior Security

Senior Security

by alirezarezvani · v1.0.0

Research
ClawHub
8.6
/ 10
1 evaluations
1.7k Downloads

Overview

Provide a structured, senior-level security engineering toolkit for threat modeling, secure architecture design, vulnerability assessment, secure code review, and incident response, including concrete workflows, checklists, and reference patterns.

Key Advantages

1.End-to-end coverage of the security engineering lifecycle: threat modeling, architecture, assessment, code review, and incident response are all represented with clear workflows.
2.Highly structured, step-by-step workflows (with validation criteria) that map well to how an AI assistant can reason and ask clarifying questions during security tasks.
3.Grounded in established frameworks and methodologies (STRIDE, DREAD, defense-in-depth, Zero Trust, OWASP Top 10, standard incident response phases).
4.Practical checklists and matrices (STRIDE per element, severity matrices, security headers, code review checklist) that can translate directly into systematic AI-guided reviews.
5.Includes specific tool recommendations across SAST/DAST, dependency scanning, secrets detection, containers, infra, and pentest tooling, enabling realistic, actionable guidance for users with real dev

Use Cases

  • Guiding a structured STRIDE-based threat model for a user’s system, including assets, trust boundaries, DFD creation, and DREAD-style scoring.
  • Reviewing or designing application and infrastructure security architectures using defense-in-depth and Zero Trust principles, including authn/z and encryption strategies.
  • Planning and executing vulnerability assessments that combine automated scanners with manual business-logic and authz testing, plus severity-based remediation plans.
  • Conducting secure code reviews focused on auth/authz, input validation, injection, crypto, and secrets, using the provided checklists and secure vs. insecure patterns.
  • Designing and iterating incident response playbooks, including triage, containment, eradication, recovery, and lessons-learned workflows aligned with severity levels (P1–P4).

Evaluation Scores

8.6
/ 10
Reliability
8.3
Functionality
8.8
Usability
8.8
Safety
8.7
Performance
9.0
Compatibility
8.0

Based on 1 evaluation · Latest: 3/20/2026

Download Trend

Loading...

Evaluation History (1)

8.6/103/20/2026
▼
OS: linux-x64LLM: google/gemini-2.5-flash-lite
**Judgment:** Strong, well-structured security engineering skill suitable for senior engineers, security leads, and security-minded architects. It offers comprehensive workflows and checklists that an AI can follow to deliver methodical, defensible security guidance. **Main strengths** - Covers the full lifecycle: threat modeling (STRIDE + DREAD), secure architecture, vulnerability assessment, secure code review, and incident response. - Provides explicit workflows with validation steps, making it easier for the assistant to stay systematic and avoid skipping critical checks. - Includes concrete matrices and checklists (STRIDE per element, severity matrices, security headers, secure vs insecure coding patterns, IR phases) that support consistent, repeatable evaluations. - Practical references to tools and algorithms (SAST/DAST, secrets scanning, AES-GCM, Argon2id, Ed25519, X25519, TLS 1.3), enabling realistic and current security recommendations. **Risks / Limitations** - Focuses primarily on web/app and typical enterprise/cloud security; less explicit coverage for niche domains (e.g., OT/ICS, IoT, mobile specifics), so the assistant may need to generalize beyond what’s written. - Uses DREAD for risk scoring, which is less commonly used than CVSS in some organizations; the assistant should avoid over-claiming alignment with all industry standards. - References offensive tools (e.g., Metasploit, sqlmap) in a defensive/assessment context; the assistant must ensure it does not facilitate misuse or unauthorized testing. **Recommended scenarios** - When users ask for a structured threat model, secure architecture review, or code review of a system/service. - For teams designing or refining incident response runbooks or security operations workflows. - For developers or DevOps/DevSecOps teams seeking actionable, stepwise guidance on hardening applications, infrastructure, and CI/CD pipelines. - As a backbone for senior-level security consultations where rigor, coverage, and traceability of reasoning are important (e.g., pre-audit reviews, pre-launch security assessments).

Comments (0)

Post a Comment

No comments yet. Be the first!