safety-review
Run an AI safety review for a feature/model — harms, evaluations, guardrails, and a documented safety case.
Build a board/executive security brief — strategy, quantified risk, and a board-ready deck.
> /plugin marketplace add jassics/awesome-claude-securityHow it fires
How this command gets triggered: by you, by Claude, or both.
/board-briefContext preview
What this command does when you run it.
Build a board/executive security brief — strategy, quantified risk, and a board-ready deck.
description: Build a board/executive security brief — strategy, quantified risk, and a board-ready deck. argument-hint: [audience + focus, e.g. "Q3 board: ransomware posture"]
Build an executive security brief for: **$ARGUMENTS**
Walk it, using installed skills (note any whose plugin is missing):
1. **Strategy frame** — `/ciso-toolkit:security-strategy` to anchor the narrative to the program's goals and roadmap. 2. **Quantify risk** — `/ciso-toolkit:cyber-risk-quantification` to put top risks in financial/likelihood terms the board understands (avoid heat-map-only framing). 3. **Contextualize** — pull the threat picture from `/threat-modeling:risk-rank` or current intel so the risks are concrete. 4. **Deck** — `/ciso-toolkit:board-deck` for the slides; `/security-reporting:executive-summary` for the written brief; `/security-diagramming:infographic` for the one-slide posture visual.
For deep execution, hand off to the `ciso` agent. Lead with decisions and asks (budget, risk acceptance, priorities), not activity metrics — the board wants "what should we decide," not "what did the team do."
A Claude Code plugin marketplace for the full cybersecurity & GenAI-security lifecycle — from recon and threat modeling to detection engineering, GRC, and CISO-level strategy. A pentester knows which OWASP test bends a broken-access-control endpoint.
Repo: jassics/awesome-claude-security
Run an AI safety review for a feature/model — harms, evaluations, guardrails, and a documented safety case.
Run a threat-informed defense cycle for a technique or threat — coverage check, hunt, detection, and purple-team validation.
Assess technology/security risk for a strategic decision and frame the secure-by-design path.
Run the pre-commit security gate on the current changeset and report a single pass/fail verdict.
Run a compliance gap-assessment for a framework, tie gaps to risk, and produce findings + remediation.
Run an authorized penetration test end-to-end, chaining recon, testing, and reporting skills into one flow.