AI Agent Hub
Back to skills
🔒

Cybersecurity Defense Expert

IT Ops & Security Updated 2026.08.30

Paste the following prompt into your AI chat to install this skill:

Please follow https://skillhub.cn/install/skillhub.md to install @user_ce145526/ba-capability-008.

About this skill

Problem

When security teams need to turn scattered requirements into an executable defense system, the hard part is usually not a lack of checklist items, but the absence of a consistent analysis framework. Compliance checks, vulnerability management, data security, AI security, penetration testing, and incident drills often live in separate processes and become one-off remediation instead of a normalized mechanism. ba-capability-008 targets consulting, assessment, and planning questions, helping turn requirements into current-state assessment, improvement suggestions, implementation path, and reference standards.

How It Works

The skill starts by identifying the concrete pain point, goal, and scope from the user's description, then analyzes the situation against industry best practices and standards. Key steps include:
- Understanding needs: determining whether the issue is a compliance gap, technology adoption, weak drills, or insufficient vulnerability response.
- Professional analysis: comparing current state with target state, and evaluating feasibility, dependencies, cost, and risk.
- Output recommendations: producing structured results that cover current-state assessment, actionable improvements, sequencing, caveats, and relevant industry standards or benchmark practices.
Its scope is comprehensive and can touch compliance checks, vulnerability management, data security, AI security, penetration testing, and incident drills, with the focus on helping form a reviewable, actionable defense mechanism rather than performing offensive operations.

Boundaries

It is suitable for security program planning, solution review, capability gap analysis, and remediation path design, especially for teams that need to connect business scenarios, technology stacks, and compliance requirements. For concrete exploit development, code auditing, log forensics, or live incident response execution, it should be used together with specialized security tools and on-scene evidence, not as a substitute for actual security testing.

Use Cases

  • A security lead plans an annual red-team drill and needs to map gaps, workflow, scoring, and review steps.
  • A compliance team prepares for an audit by listing controls, evidence gaps, remediation steps, and references.
  • A platform team evaluates AI product security before launch, covering data access, prompt injection, logs, and rollback.
  • A vulnerability team converts scan alerts into a fix workflow, defining severity, retest points, and ownership.

Best For

  • A security architect needs to turn scattered controls into a reviewable defense framework.
  • A compliance manager needs to identify policy gaps and prioritize remediation before an audit.
  • A technical leader needs to explain security spending priorities and implementation path to management.
  • An AI product owner needs to assess model permissions, injection risks, data boundaries, and rollback plans.