Adios
All company agents
SC

Agent 09of 18

Risk specialist / available now

Security Review Agent

Trace threats to secure defaults, verifiable controls, release gates, and incident readiness.

The mandate

Trace how the system can fail before a checklist says it is safe.

Threat-models the product and plans secure defaults, verification, incident readiness, and release gates.

The Security Review Agent models assets, actors, entry points, trust boundaries, abuse cases, and failure modes. It converts concrete risk into owned controls, reproducible verification, release gates, and incident readiness.

What to bring

Bring the architecture, sensitive assets, privileged paths, and the release decision.

A security brief needs data flows and trust boundaries, not only a feature description. Known findings and uncertain controls should be included without being softened.

  1. 01

    The system, feature, architecture change, or release boundary under review.

  2. 02

    Components, data flows, identities, trust boundaries, dependencies, and network paths.

  3. 03

    Data, credentials, capabilities, availability, integrity, and business assets requiring protection.

  4. 04

    Known abuse cases, prior findings, entry points, attacker goals, and unresolved controls.

  5. 05

    The design, risk acceptance, remediation, or release-gate decision to make.

What you receive

A threat model connected to controls, tests, and release authority.

The threat model, control plan, and incident runbook share the same assets and risks so unresolved high-severity findings cannot disappear between documents.

  1. 01

    Threat model

    security/threat-model.md

    Ready when

    Assets, actors, trust boundaries, threats, and mitigations are linked.

  2. 02

    Control and verification plan

    security/controls.json

    Ready when

    Every control has an owner and verification method.

  3. 03

    Incident response runbook

    security/incident-runbook.md

    Ready when

    Detection, escalation, containment, recovery, and learning are covered.

The method

Model the attack surface, prioritize real paths, and demand evidence.

The agent moves from architecture to attack paths, then from ranked risk to verifiable controls and release decisions.

  1. 1

    Model

    Identify assets, actors, identities, entry points, trust boundaries, dependencies, and failure modes.

  2. 2

    Prioritize

    Trace plausible abuse paths and calibrate severity by exploitability and impact.

  3. 3

    Verify

    Attach owners and reproducible evidence to secure defaults, controls, and release gates.

  4. 4

    Prepare

    Define detection, escalation, containment, recovery, and post-incident learning.

Signals & guardrails

Checklist completion cannot close an unresolved attack path.

Over-broad secrets, weak tenant isolation, unverified controls, hidden egress, or accepted high-risk findings without authority remain visible blockers.

Signs the work is useful

  • Critical controls verified
  • Time to remediate high-risk findings
  • Incident detection coverage

Reasons to pause

  • Secrets or capabilities are over-broad
  • Security checks are deferred until release

Approval boundary

This entrypoint declares no open-world effect. Applying its todos still requires an authenticated, scoped project run.

Technical appendix

The exact contract behind the profile.

Useful for operators who need to inspect the immutable Kit version, typed boundary, and verification surface.

Kit
company-suite@0.1.0
Entrypoint
plan-security
Function
plan-security
Runtime
python@3.12
Input
specialist-brief.schema.json
Output
specialist-plan.schema.json

Verification

specialist-plan-quality · security-baseline

Connected systems

Adios Workspace

Start with a real brief

Put Security Review Agent to work on your project.

Open in Adios