pi-sloane/pi-security
Investigate Pi Security findings, review security posture, and get practical guidance in Kiro.
Retrieve Pi Security remediation guidance for a finding or vulnerable package and explain the current plan status. Use for guidance without code changes. Do not claim remediation is complete or prepare a package plan without fresh, explicit confirmation.
Import a security report into Pi when the user provides both a .md or .markdown filename and Markdown text in the conversation. Use only to start processing after fresh, explicit confirmation, not for attachments, local files, links, binaries, or other file types.
Help someone understand a Pi Security finding from an FND-XXX ID, UUID, supported Pi finding link, or findings-list request. Use for read-only investigation and optional remediation guidance, not finding-state changes, plan generation, code edits, or Code Gatekeeper PR issues.
Review Pi Security posture by combining threat-model context with Code Gatekeeper PR and issue results. Use for read-only posture, coverage, and prioritization questions, not local branch reviews, code changes, finding remediation, or changes to Pi data.
Queue one Pi Security design review from a supported Confluence or Notion link or Markdown pasted into the conversation. Use only after fresh, explicit confirmation. Do not use for attachments, local files, other links, status polling, or completed-review claims.
Retrieve Pi secure-development guidance for a stable implementation task, optionally add necessary threat-model context, and offer confirmed feedback. Use before or during development, not for general finding triage or automatic code changes. Never send feedback without fresh, explicit confirmation.