{"id":"1fdd7b6a-0e6f-4286-98f4-5f5c8778cdb2","entityType":"agent","slug":"clawhub-skills-alirezarezvani-senior-security","name":"senior-security","canonicalUrl":"https://www.xpersona.co/agent/clawhub-skills-alirezarezvani-senior-security","canonicalPath":"/agent/clawhub-skills-alirezarezvani-senior-security","generatedAt":"2026-10-09T18:38:04.368Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"description":"Security engineering toolkit for threat modeling, vulnerability analysis, secure architecture, and penetration testing. Includes STRIDE analysis, OWASP guidance, cryptography patterns, and security scanning tools. --- name: senior-security description: Security engineering toolkit for threat modeling, vulnerability analysis, secure architecture, and penetration testing. Includes STRIDE analysis, OWASP guidance, cryptography patterns, and security scanning tools. triggers: - security architecture - threat modeling - STRIDE analysis - penetration testing - vulnerability assessment - secure coding - OWASP - application security -","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. Last updated 4/15/2026.","installCommand":"clawhub skill install skills:alirezarezvani:senior-security","sourceUrl":"https://github.com/openclaw/skills/tree/main/skills/alirezarezvani/senior-security","homepage":null,"primaryLinks":[{"label":"View on ClawHub","url":"https://github.com/openclaw/skills/tree/main/skills/alirezarezvani/senior-security","kind":"source"}],"safetyScore":84,"overallRank":62,"popularityScore":50,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Security engineering toolkit for threat modeling, vulnerability analysis, secure architecture, and penetration testing. Includes STRIDE analysis, OWASP guidance"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[{"label":"identity","status":"self-declared"},{"label":"data","status":"self-declared"},{"label":"actions","status":"self-declared"},{"label":"availability","status":"self-declared"},{"label":"access","status":"self-declared"},{"label":"20","status":"self-declared"}],"verifiedCount":0,"selfDeclaredCount":7,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"},{"key":"identity","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"data","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"actions","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"availability","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"access","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"20","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile capability:identity|supported|profile capability:data|supported|profile capability:actions|supported|profile capability:availability|supported|profile capability:access|supported|profile capability:20|supported|profile"}},"adoption":{"evidence":{"source":"no-adoption-signals","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"No source adoption metrics were available."},"stars":null,"forks":null,"downloads":null,"packageName":null,"latestVersion":null,"tractionLabel":null},"release":{"evidence":{"source":"agent-index","verified":false,"confidence":"medium","updatedAt":"2026-02-25T03:34:57.577Z","emptyReason":null},"lastUpdatedAt":"2026-04-15T00:45:39.800Z","lastCrawledAt":"2026-02-25T03:34:57.577Z","lastIndexedAt":null,"nextCrawlAt":"2026-02-26T03:34:57.577Z","lastVerifiedAt":null,"highlights":[]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install skills:alirezarezvani:senior-security","setupComplexity":"low","setupSteps":["Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-alirezarezvani-senior-security/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-alirezarezvani-senior-security/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-alirezarezvani-senior-security/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-skills-alirezarezvani-senior-security/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-skills-alirezarezvani-senior-security/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-skills-alirezarezvani-senior-security/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-09T18:38:04.367Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-alirezarezvani-senior-security/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-alirezarezvani-senior-security/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-alirezarezvani-senior-security/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-alirezarezvani-senior-security/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"readme":"---\nname: senior-security\ndescription: Security engineering toolkit for threat modeling, vulnerability analysis, secure architecture, and penetration testing. Includes STRIDE analysis, OWASP guidance, cryptography patterns, and security scanning tools.\ntriggers:\n  - security architecture\n  - threat modeling\n  - STRIDE analysis\n  - penetration testing\n  - vulnerability assessment\n  - secure coding\n  - OWASP\n  - application security\n  - cryptography implementation\n  - secret scanning\n  - security audit\n  - zero trust\n---\n\n# Senior Security Engineer\n\nSecurity engineering tools for threat modeling, vulnerability analysis, secure architecture design, and penetration testing.\n\n---\n\n## Table of Contents\n\n- [Threat Modeling Workflow](#threat-modeling-workflow)\n- [Security Architecture Workflow](#security-architecture-workflow)\n- [Vulnerability Assessment Workflow](#vulnerability-assessment-workflow)\n- [Secure Code Review Workflow](#secure-code-review-workflow)\n- [Incident Response Workflow](#incident-response-workflow)\n- [Security Tools Reference](#security-tools-reference)\n- [Tools and References](#tools-and-references)\n\n---\n\n## Threat Modeling Workflow\n\nIdentify and analyze security threats using STRIDE methodology.\n\n### Workflow: Conduct Threat Model\n\n1. Define system scope and boundaries:\n   - Identify assets to protect\n   - Map trust boundaries\n   - Document data flows\n2. Create data flow diagram:\n   - External entities (users, services)\n   - Processes (application components)\n   - Data stores (databases, caches)\n   - Data flows (APIs, network connections)\n3. Apply STRIDE to each DFD element:\n   - Spoofing: Can identity be faked?\n   - Tampering: Can data be modified?\n   - Repudiation: Can actions be denied?\n   - Information Disclosure: Can data leak?\n   - Denial of Service: Can availability be affected?\n   - Elevation of Privilege: Can access be escalated?\n4. Score risks using DREAD:\n   - Damage potential (1-10)\n   - Reproducibility (1-10)\n   - Exploitability (1-10)\n   - Affected users (1-10)\n   - Discoverability (1-10)\n5. Prioritize threats by risk score\n6. Define mitigations for each threat\n7. Document in threat model report\n8. **Validation:** All DFD elements analyzed; STRIDE applied; threats scored; mitigations mapped\n\n### STRIDE Threat Categories\n\n| Category | Description | Security Property | Mitigation Focus |\n|----------|-------------|-------------------|------------------|\n| Spoofing | Impersonating users or systems | Authentication | MFA, certificates, strong auth |\n| Tampering | Modifying data or code | Integrity | Signing, checksums, validation |\n| Repudiation | Denying actions | Non-repudiation | Audit logs, digital signatures |\n| Information Disclosure | Exposing data | Confidentiality | Encryption, access controls |\n| Denial of Service | Disrupting availability | Availability | Rate limiting, redundancy |\n| Elevation of Privilege | Gaining unauthorized access | Authorization | RBAC, least privilege |\n\n### STRIDE per Element Matrix\n\n| DFD Element | S | T | R | I | D | E |\n|-------------|---|---|---|---|---|---|\n| External Entity | X | | X | | | |\n| Process | X | X | X | X | X | X |\n| Data Store | | X | X | X | X | |\n| Data Flow | | X | | X | X | |\n\nSee: [references/threat-modeling-guide.md](references/threat-modeling-guide.md)\n\n---\n\n## Security Architecture Workflow\n\nDesign secure systems using defense-in-depth principles.\n\n### Workflow: Design Secure Architecture\n\n1. Define security requirements:\n   - Compliance requirements (GDPR, HIPAA, PCI-DSS)\n   - Data classification (public, internal, confidential, restricted)\n   - Threat model inputs\n2. Apply defense-in-depth layers:\n   - Perimeter: WAF, DDoS protection, rate limiting\n   - Network: Segmentation, IDS/IPS, mTLS\n   - Host: Patching, EDR, hardening\n   - Application: Input validation, authentication, secure coding\n   - Data: Encryption at rest and in transit\n3. Implement Zero Trust principles:\n   - Verify explicitly (every request)\n   - Least privilege access (JIT/JEA)\n   - Assume breach (segment, monitor)\n4. Configure authentication and authorization:\n   - Identity provider selection\n   - MFA requirements\n   - RBAC/ABAC model\n5. Design encryption strategy:\n   - Key management approach\n   - Algorithm selection\n   - Certificate lifecycle\n6. Plan security monitoring:\n   - Log aggregation\n   - SIEM integration\n   - Alerting rules\n7. Document architecture decisions\n8. **Validation:** Defense-in-depth layers defined; Zero Trust applied; encryption strategy documented; monitoring planned\n\n### Defense-in-Depth Layers\n\n```\nLayer 1: PERIMETER\n  WAF, DDoS mitigation, DNS filtering, rate limiting\n\nLayer 2: NETWORK\n  Segmentation, IDS/IPS, network monitoring, VPN, mTLS\n\nLayer 3: HOST\n  Endpoint protection, OS hardening, patching, logging\n\nLayer 4: APPLICATION\n  Input validation, authentication, secure coding, SAST\n\nLayer 5: DATA\n  Encryption at rest/transit, access controls, DLP, backup\n```\n\n### Authentication Pattern Selection\n\n| Use Case | Recommended Pattern |\n|----------|---------------------|\n| Web application | OAuth 2.0 + PKCE with OIDC |\n| API authentication | JWT with short expiration + refresh tokens |\n| Service-to-service | mTLS with certificate rotation |\n| CLI/Automation | API keys with IP allowlisting |\n| High security | FIDO2/WebAuthn hardware keys |\n\nSee: [references/security-architecture-patterns.md](references/security-architecture-patterns.md)\n\n---\n\n## Vulnerability Assessment Workflow\n\nIdentify and remediate security vulnerabilities in applications.\n\n### Workflow: Conduct Vulnerability Assessment\n\n1. Define assessment scope:\n   - In-scope systems and applications\n   - Testing methodology (black box, gray box, white box)\n   - Rules of engagement\n2. Gather information:\n   - Technology stack inventory\n   - Architecture documentation\n   - Previous vulnerability reports\n3. Perform automated scanning:\n   - SAST (static analysis)\n   - DAST (dynamic analysis)\n   - Dependency scanning\n   - Secret detection\n4. Conduct manual testing:\n   - Business logic flaws\n   - Authentication bypass\n   - Authorization issues\n   - Injection vulnerabilities\n5. Classify findings by severity:\n   - Critical: Immediate exploitation risk\n   - High: Significant impact, easier to exploit\n   - Medium: Moderate impact or difficulty\n   - Low: Minor impact\n6. Develop remediation plan:\n   - Prioritize by risk\n   - Assign owners\n   - Set deadlines\n7. Verify fixes and document\n8. **Validation:** Scope defined; automated and manual testing complete; findings classified; remediation tracked\n\n### OWASP Top 10 Mapping\n\n| Rank | Vulnerability | Testing Approach |\n|------|---------------|------------------|\n| A01 | Broken Access Control | Manual IDOR testing, authorization checks |\n| A02 | Cryptographic Failures | Algorithm review, key management audit |\n| A03 | Injection | SAST + manual payload testing |\n| A04 | Insecure Design | Threat modeling, architecture review |\n| A05 | Security Misconfiguration | Configuration audit, CIS benchmarks |\n| A06 | Vulnerable Components | Dependency scanning, CVE monitoring |\n| A07 | Authentication Failures | Password policy, session management review |\n| A08 | Software/Data Integrity | CI/CD security, code signing verification |\n| A09 | Logging Failures | Log review, SIEM configuration check |\n| A10 | SSRF | Manual URL manipulation testing |\n\n### Vulnerability Severity Matrix\n\n| Impact / Exploitability | Easy | Moderate | Difficult |\n|-------------------------|------|----------|-----------|\n| Critical | Critical | Critical | High |\n| High | Critical | High | Medium |\n| Medium | High | Medium | Low |\n| Low | Medium | Low | Low |\n\n---\n\n## Secure Code Review Workflow\n\nReview code for security vulnerabilities before deployment.\n\n### Workflow: Conduct Security Code Review\n\n1. Establish review scope:\n   - Changed files and functions\n   - Security-sensitive areas (auth, crypto, input handling)\n   - Third-party integrations\n2. Run automated analysis:\n   - SAST tools (Semgrep, CodeQL, Bandit)\n   - Secret scanning\n   - Dependency vulnerability check\n3. Review authentication code:\n   - Password handling (hashing, storage)\n   - Session management\n   - Token validation\n4. Review authorization code:\n   - Access control checks\n   - RBAC implementation\n   - Privilege boundaries\n5. Review data handling:\n   - Input validation\n   - Output encoding\n   - SQL query construction\n   - File path handling\n6. Review cryptographic code:\n   - Algorithm selection\n   - Key management\n   - Random number generation\n7. Document findings with severity\n8. **Validation:** Automated scans passed; auth/authz reviewed; data handling checked; crypto verified; findings documented\n\n### Security Code Review Checklist\n\n| Category | Check | Risk |\n|----------|-------|------|\n| Input Validation | All user input validated and sanitized | Injection |\n| Output Encoding | Context-appropriate encoding applied | XSS |\n| Authentication | Passwords hashed with Argon2/bcrypt | Credential theft |\n| Session | Secure cookie flags set (HttpOnly, Secure, SameSite) | Session hijacking |\n| Authorization | Server-side permission checks on all endpoints | Privilege escalation |\n| SQL | Parameterized queries used exclusively | SQL injection |\n| File Access | Path traversal sequences rejected | Path traversal |\n| Secrets | No hardcoded credentials or keys | Information disclosure |\n| Dependencies | Known vulnerable packages updated | Supply chain |\n| Logging | Sensitive data not logged | Information disclosure |\n\n### Secure vs Insecure Patterns\n\n| Pattern | Issue | Secure Alternative |\n|---------|-------|-------------------|\n| SQL string formatting | SQL injection | Use parameterized queries with placeholders |\n| Shell command building | Command injection | Use subprocess with argument lists, no shell |\n| Path concatenation | Path traversal | Validate and canonicalize paths |\n| MD5/SHA1 for passwords | Weak hashing | Use Argon2id or bcrypt |\n| Math.random for tokens | Predictable values | Use crypto.getRandomValues |\n\n---\n\n## Incident Response Workflow\n\nRespond to and contain security incidents.\n\n### Workflow: Handle Security Incident\n\n1. Identify and triage:\n   - Validate incident is genuine\n   - Assess initial scope and severity\n   - Activate incident response team\n2. Contain the threat:\n   - Isolate affected systems\n   - Block malicious IPs/accounts\n   - Disable compromised credentials\n3. Eradicate root cause:\n   - Remove malware/backdoors\n   - Patch vulnerabilities\n   - Update configurations\n4. Recover operations:\n   - Restore from clean backups\n   - Verify system integrity\n   - Monitor for recurrence\n5. Conduct post-mortem:\n   - Timeline reconstruction\n   - Root cause analysis\n   - Lessons learned\n6. Implement improvements:\n   - Update detection rules\n   - Enhance controls\n   - Update runbooks\n7. Document and report\n8. **Validation:** Threat contained; root cause eliminated; systems recovered; post-mortem complete; improvements implemented\n\n### Incident Severity Levels\n\n| Level | Description | Response Time | Escalation |\n|-------|-------------|---------------|------------|\n| P1 - Critical | Active breach, data exfiltration | Immediate | CISO, Legal, Executive |\n| P2 - High | Confirmed compromise, contained | 1 hour | Security Lead, IT Director |\n| P3 - Medium | Potential compromise, under investigation | 4 hours | Security Team |\n| P4 - Low | Suspicious activity, low impact | 24 hours | On-call engineer |\n\n### Incident Response Checklist\n\n| Phase | Actions |\n|-------|---------|\n| Identification | Validate alert, assess scope, determine severity |\n| Containment | Isolate systems, preserve evidence, block access |\n| Eradication | Remove threat, patch vulnerabilities, reset credentials |\n| Recovery | Restore services, verify integrity, increase monitoring |\n| Lessons Learned | Document timeline, identify gaps, update procedures |\n\n---\n\n## Security Tools Reference\n\n### Recommended Security Tools\n\n| Category | Tools |\n|----------|-------|\n| SAST | Semgrep, CodeQL, Bandit (Python), ESLint security plugins |\n| DAST | OWASP ZAP, Burp Suite, Nikto |\n| Dependency Scanning | Snyk, Dependabot, npm audit, pip-audit |\n| Secret Detection | GitLeaks, TruffleHog, detect-secrets |\n| Container Security | Trivy, Clair, Anchore |\n| Infrastructure | Checkov, tfsec, ScoutSuite |\n| Network | Wireshark, Nmap, Masscan |\n| Penetration | Metasploit, sqlmap, Burp Suite Pro |\n\n### Cryptographic Algorithm Selection\n\n| Use Case | Algorithm | Key Size |\n|----------|-----------|----------|\n| Symmetric encryption | AES-256-GCM | 256 bits |\n| Password hashing | Argon2id | N/A (use defaults) |\n| Message authentication | HMAC-SHA256 | 256 bits |\n| Digital signatures | Ed25519 | 256 bits |\n| Key exchange | X25519 | 256 bits |\n| TLS | TLS 1.3 | N/A |\n\nSee: [references/cryptography-implementation.md](references/cryptography-implementation.md)\n\n---\n\n## Tools and References\n\n### Scripts\n\n| Script | Purpose | Usage |\n|--------|---------|-------|\n| [threat_modeler.py](scripts/threat_modeler.py) | STRIDE threat analysis with risk scoring | `python threat_modeler.py --component \"Authentication\"` |\n| [secret_scanner.py](scripts/secret_scanner.py) | Detect hardcoded secrets and credentials | `python secret_scanner.py /path/to/project` |\n\n**Threat Modeler Features:**\n- STRIDE analysis for any system component\n- DREAD risk scoring\n- Mitigation recommendations\n- JSON and text output formats\n- Interactive mode for guided analysis\n\n**Secret Scanner Features:**\n- Detects AWS, GCP, Azure credentials\n- Finds API keys and tokens (GitHub, Slack, Stripe)\n- Identifies private keys and passwords\n- Supports 20+ secret patterns\n- CI/CD integration ready\n\n### References\n\n| Document | Content |\n|----------|---------|\n| [security-architecture-patterns.md](references/security-architecture-patterns.md) | Zero Trust, defense-in-depth, authentication patterns, API security |\n| [threat-modeling-guide.md](references/threat-modeling-guide.md) | STRIDE methodology, attack trees, DREAD scoring, DFD creation |\n| [cryptography-implementation.md](references/cryptography-implementation.md) | AES-GCM, RSA, Ed25519, password hashing, key management |\n\n---\n\n## Security Standards Reference\n\n### Compliance Frameworks\n\n| Framework | Focus | Applicable To |\n|-----------|-------|---------------|\n| OWASP ASVS | Application security | Web applications |\n| CIS Benchmarks | System hardening | Servers, containers, cloud |\n| NIST CSF | Risk management | Enterprise security programs |\n| PCI-DSS | Payment card data | Payment processing |\n| HIPAA | Healthcare data | Healthcare applications |\n| SOC 2 | Service organization controls | SaaS providers |\n\n### Security Headers Checklist\n\n| Header | Recommended Value |\n|--------|-------------------|\n| Content-Security-Policy | default-src self; script-src self |\n| X-Frame-Options | DENY |\n| X-Content-Type-Options | nosniff |\n| Strict-Transport-Security | max-age=31536000; includeSubDomains |\n| Referrer-Policy | strict-origin-when-cross-origin |\n| Permissions-Policy | geolocation=(), microphone=(), camera=() |\n\n---\n\n## Related Skills\n\n| Skill | Integration Point |\n|-------|-------------------|\n| [senior-devops](../senior-devops/) | CI/CD security, infrastructure hardening |\n| [senior-secops](../senior-secops/) | Security monitoring, incident response |\n| [senior-backend](../senior-backend/) | Secure API development |\n| [senior-architect](../senior-architect/) | Security architecture decisions |\n","readmeExcerpt":"--- name: senior-security description: Security engineering toolkit for threat modeling, vulnerability analysis, secure architecture, and penetration testing. Includes STRIDE analysis, OWASP guidance, cryptography patterns, and security scanning tools. triggers: - security architecture - threat modeling - STRIDE analysis - penetration testing - vulnerability assessment - secure coding - OWASP - application security -","codeSnippets":[],"executableExamples":[{"language":"text","snippet":"Layer 1: PERIMETER\n  WAF, DDoS mitigation, DNS filtering, rate limiting\n\nLayer 2: NETWORK\n  Segmentation, IDS/IPS, network monitoring, VPN, mTLS\n\nLayer 3: HOST\n  Endpoint protection, OS hardening, patching, logging\n\nLayer 4: APPLICATION\n  Input validation, authentication, secure coding, SAST\n\nLayer 5: DATA\n  Encryption at rest/transit, access controls, DLP, backup"}],"parameters":{},"dependencies":[],"permissions":[],"extractedFiles":[],"languages":["typescript"],"docsSourceLabel":"CLAWHUB","editorialOverview":"Security engineering toolkit for threat modeling, vulnerability analysis, secure architecture, and penetration testing. Includes STRIDE analysis, OWASP guidance, cryptography patterns, and security scanning tools. --- name: senior-security description: Security engineering toolkit for threat modeling, vulnerability analysis, secure architecture, and penetration testing. Includes STRIDE analysis, OWASP guidance, cryptography patterns, and security scanning tools. triggers: - security architecture - threat modeling - STRIDE analysis - penetration testing - vulnerability assessment - secure coding - OWASP - application security -","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":371,"uniquenessScore":64,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T18:38:04.368Z","emptyReason":null},"items":[{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-10T18:48:31.762Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}