Skip to content

pi-sloane/pi-security

v0.1.0MIT

Investigate Pi Security findings, review security posture, and get practical guidance in Kiro.

get-pi-remediation-guidance

Retrieve Pi Security remediation guidance for a finding or vulnerable package and explain the current plan status. Use for guidance without code changes. Do not claim remediation is complete or prepare a package plan without fresh, explicit confirmation.

ingest-pi-markdown-report

Import a security report into Pi when the user provides both a .md or .markdown filename and Markdown text in the conversation. Use only to start processing after fresh, explicit confirmation, not for attachments, local files, links, binaries, or other file types.

investigate-pi-finding

Help someone understand a Pi Security finding from an FND-XXX ID, UUID, supported Pi finding link, or findings-list request. Use for read-only investigation and optional remediation guidance, not finding-state changes, plan generation, code edits, or Code Gatekeeper PR issues.

review-pi-security-posture

Review Pi Security posture by combining threat-model context with Code Gatekeeper PR and issue results. Use for read-only posture, coverage, and prioritization questions, not local branch reviews, code changes, finding remediation, or changes to Pi data.

start-pi-security-design-review

Queue one Pi Security design review from a supported Confluence or Notion link or Markdown pasted into the conversation. Use only after fresh, explicit confirmation. Do not use for attachments, local files, other links, status polling, or completed-review claims.

use-pi-secure-development-playbook

Retrieve Pi secure-development guidance for a stable implementation task, optionally add necessary threat-model context, and offer confirmed feedback. Use before or during development, not for general finding triage or automatic code changes. Never send feedback without fresh, explicit confirmation.