From cto-security
Assess the security risk of a technology or product decision for leadership — new technology/vendor adoption, build-vs-buy, third-party/supply-chain, or M&A technical due diligence — and give a clear recommendation with trade-offs. Use to inform a strategic technology decision.
How this skill is triggered — by the user, by Claude, or both
Slash command
/cto-security:tech-risk-assessmentThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
A decision-ready security risk assessment of the option(s) under consideration, with
A decision-ready security risk assessment of the option(s) under consideration, with a recommendation that weighs security against velocity, cost, and strategic fit.
threat-modeling).A tech-risk assessment: decision · options · per-option security posture · third- party/integration/data risk · total cost incl. security · recommendation + conditions
security-reporting; diagram integration/trust boundaries with
security-diagramming.Decide with explicit trade-offs, not security absolutism — the goal is the best risk-adjusted technology choice for the business. Weight third-party/supply-chain and exit/lock-in risk; they're routinely underestimated. State residual risk and the conditions under which the recommendation holds.
Provides CDSS development patterns for drug interaction checking, dose validation, clinical scoring (NEWS2, qSOFA), and alert classification integrated into EMR workflows.
npx claudepluginhub jassics/awesome-claude-security --plugin cto-security