007 — Licença para Auditar Skill · Testing Security
007: Professional Security Audit & Threat Modeling AI Agent
Secure your code with 007.
Expert threat modeling and OWASP checks across 8 critical domains. Audit infrastructure and APIs to prevent breaches today.
Cybersecurity
Threat Modeling
OWASP
DevSecOps
Penetration Testing
About This Skill
The 007 skill transforms your AI into a Chief Security Architect. Covering 8 specialized domains from infrastructure to LLM security, it provides comprehensive hardening using STRIDE and PASTA methodologies for robust software protection.
Quick Start
1Install the antigravity CLI
2Add the 007 skill to your project environment
3Run the audit command on your target codebase or infrastructure
Example Command
antigravity run 007 'Perform a STRIDE threat model on my API'
Core Capabilities
Codigo
Expert SAST, dependency checks, and supply chain security for Python and Node/JS.
Infra
Hardening for Linux, Windows, SSH, firewalls, containers, and cloud environments.
APIs
Security audits for REST, GraphQL, OAuth, JWT, and rate limiting implementations.
IA/Agentes
Protection against prompt injection, jailbreaking, and LLM-specific security risks.
Usage Examples
Before
Vulnerable auth with plain text storage and no rate limits.
After
Hardened auth with Argon2, secure JWT secrets, and rate limiting.
Input
Perform a STRIDE threat model on this microservice.
Output
Generated STRIDE report: Spoofing risk in inter-service comms, Tampering risk in DB logs.
Input
Check my Dockerfile for security issues.
Output
Found root user execution. Suggested non-root user and multi-stage build.
SKILL.md
---
name: '007'
description: Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.
risk: critical
source: community
date_added: '2026-03-06'
author: renat
tags:
- security
- audit
- owasp
- threat-modeling
- hardening
- pentest
tools:
- claude-code
- antigravity
- cursor
- gemini-cli
- codex-cli
---
# 007 — Licenca para Auditar
## Overview
Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.
## When to Use This Skill
- When the user mentions "audite" or related topics
- When the user mentions "auditoria" or related topics
- When the user mentions "seguranca" or related topics
- When the user mentions "security audit" or related topics
- When the user mentions "threat model" or related topics
- When the user mentions "STRIDE" or related topics
## Do Not Use This Skill When
- The task is unrelated to 007
- A simpler, more specific tool can handle the request
- The user needs general-purpose assistance without domain expertise
## How It Works
O 007 opera como um **Chief Security Architect AI** com expertise em:
| Dominio | Especialidades |
|---------|---------------|
| **Codigo** | Python, Node/JS, supply chain, SAST, dependencias |
| **Infra** | Linux/Ubuntu, Windows, SSH, firewall, containers, VPS, cloud |
| **APIs** | REST, GraphQL, OAuth, JWT, webhooks, CORS, rate limit |
| **Bots/Social** | WhatsApp, Instagram, Telegram (anti-ban, rate limit, policies) |
| **Pagamentos** | PCI-DSS mindset, antifraude, idempotencia, webhooks financeiros |
| **IA/Agentes** | Prompt injection, jailbreak, isolamento, explosao de custo, LLM security |
| **Compliance** | OWASP Top 10 (Web/API/LLM), LGPD/GDPR, SOC2, Zero Trust |
| **Operacoes** | Observabilidade, logging, resposta a incidentes, playbooks |
## 007 — Licenca Para Auditar
Agente Supremo de Seg
Frequently Asked Questions
FAQ
Which tools is the 007 skill compatible with?
It integrates seamlessly with Claude Code, Antigravity, Cursor, Gemini-CLI, and Codex-CLI.
Who is the target audience for this skill?
It is designed for Developers, Security Architects, and DevOps engineers looking to automate security audits.
How does 007 differ from standard linters?
Unlike basic linters, 007 performs deep threat modeling (STRIDE/PASTA) and Red/Blue team analysis across 8 domains.
Does it support multiple programming languages?
Yes, it has specialized expertise in Python, Node/JS, and infrastructure-as-code like Docker and Cloud configs.
What results can I expect from a security audit?
You will receive a detailed report covering OWASP Top 10 vulnerabilities, hardening steps, and incident response playbooks.