nw-ab-critique-dimensi…
Review dimensions for validating agent quality - template compliance, safety, testing, and priority validation
Security design principles, STRIDE threat modeling, OWASP Top 10 architectural mitigations, and secure patterns. Load when designing systems or reviewing architecture for security.
$ npx -y skills add nWave-ai/nWave --skill nw-security-by-design --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/nw-security-by-designContext preview
The summary Claude sees to decide when to auto-load this skill.
Security design principles, STRIDE threat modeling, OWASP Top 10 architectural mitigations, and secure patterns. Load when designing systems or reviewing architecture for security.
name: nw-security-by-design description: Security design principles, STRIDE threat modeling, OWASP Top 10 architectural mitigations, and secure patterns. Load when designing systems or reviewing architecture for security. user-invocable: false disable-model-invocation: true
Apply these during design -- retrofitting security is 10-100x more expensive.
| # | Principle | Architect Action | |---|-----------|-----------------| | 1 | Security by Design | Include security requirements in architecture documents | | 2 | Security by Default | Ship restrictive defaults; require explicit opt-in for relaxed settings | | 3 | Defense in Depth | Layer controls: WAF + input validation + output encoding + parameterized queries | | 4 | Fail Secure | Deny access on error; closed-by-default network policies | | 5 | Least Privilege | Scoped service accounts; time-limited tokens; minimum permissions | | 6 | Compartmentalize | Network segmentation; separate databases per trust level | | 7 | Separation of Duties | Separate deployment approval from code authorship | | 8 | Economy of Mechanism | Minimize attack surface; simple, auditable security code | | 9 | Complete Mediation | Check authorization on every request; no cached auth decisions | | 10 | Open Design | Use published, peer-reviewed algorithms; no security-through-obscurity | | 11 | Least Common Mechanism | Separate admin and user interfaces | | 12 | Psychological Acceptability | Make the secure path the easy path; minimize user friction |
Apply STRIDE to every component in a Data Flow Diagram (DFD). Four questions drive every session: 1. What are we working on? (system model) 2. What can go wrong? (threat identification) 3. What are we going to do about it? (mitigation) 4. Did we do a good enough job? (review)
| Threat | Violated Property | Architectural Mitigation | |--------|-------------------|--------------------------| | **Spoofing** | Authentication | MFA, mutual TLS, certificate pinning, OAuth2+PKCE | | **Tampering** | Integrity | Input validation, HMAC, parameterized queries, immutable infra | | **Repudiation** | Non-repudiation | Tamper-evident logging (append-only), digital signatures, SIEM | | **Info Disclosure** | Confidentiality | Encryption at rest+transit, least privilege, generic error messages | | **Denial of Service** | Availability | Rate limiting, circuit breakers, auto-scaling, query complexity limits | | **Elevation of Privilege** | Authorization | Least privilege, RBAC/ABAC, signed tokens verified server-side |
| DFD Element | Most Relevant Threats | |-------------|----------------------| | External Entity | Spoofing | | Process | All six STRIDE threats | | Data Store | Tampering, Info Disclosure, Repudiation, DoS | | Data Flow | Tampering, Info Disclosure, DoS | | Trust Boundary | Spoofing, Tampering, Elevation of Privilege |
| Response | When | Example | |----------|------|---------| | Mitigate | Probable and impactful; controls feasible | Add MFA for spoofing on admin login | | Eliminate | Remove feature/component entirely | Remove unused admin API endpoint | | Transfer | Better managed by another party | Use managed IdP (Auth0, Cognito) | | Accept | Low risk; mitigation cost exceeds impact | Accept DoS risk on internal status page |
Focus on what the architect decides at design time, not implementation details.
Core: "Never trust, always verify" -- no implicit trust from network location.
| Component | Implementation | |-----------|---------------| | Identity verification | OAuth2/OIDC for users; mTLS for services | | Transport security | mTLS everywhere; service mesh (Istio, Linkerd) | | Micro-segmentation | Network policies limiting service-to-service | | Continuous verification | Re-authenticate and re-authorize every request | | Least privilege access | Sc
AI agents that guide you from idea to working code, with human judgment at every gate. nWave runs inside Claude Code. It breaks feature delivery into seven waves (discover, diverge, discuss, design, devops, distill, deliver).
Repo: nWave-ai/nWave
Review dimensions for validating agent quality - template compliance, safety, testing, and priority validation
Review dimensions for validating agent quality - template compliance, safety, testing, and priority validation
Review dimensions for acceptance test quality - happy path bias, GWT compliance, business language purity, coverage completeness, walking skeleton…
Detailed 5-phase workflow for creating agents - from requirements analysis through validation and iterative refinement
5-layer testing approach for agent validation including adversarial testing, security validation, and prompt injection resistance
Architectural style selection decision matrices, trade-off analysis, structural enforcement rules, and combination patterns. Load when choosing or evaluating…