This repository contains a spike to explore the use of AI agents for generating and maintaining security plans. The goal is to speed up the creation of security plans based on architecture and sequence diagrams, as well as to assist in the documentation process.
The primary approach is through the security-plan-creation.chatmode.md, which assists with the creation of security plans.
- Threats are generated using the anmalkov/mcp-crisp MCP server
- Chat mode for guided workflows in security plan creation and prompt engineering
- Progress is tracked by generating
.copilot-tracking/plans/<plan_name_.plan.md>files - Specialized prompts for tasks such as diagram creation and prompt refactoring
- Iterative process for refining security plans based on feedback and new information
The main functionality is provided through specialized chat modes, each designed for specific tasks in the security plan creation and prompt engineering workflow.
- Open GitHub Copilot Chat in VS Code
- Select the desired chat mode from the modes dropdown
- Choose a model that has reasoning and planning capabilities, such as
gpt-4oorClaude Sonnet 4. - Follow the guided workflow specific to the selected chat mode
- The chat modes will automatically validate prerequisites and guide you through the process
security-plan-creation.chatmode.md: Expert security architect chat mode for creating comprehensive cloud security plansprompt-builder.chatmode.md: Expert prompt engineering and validation system
Additional prompts are provided under /.github/prompts directory for specialized tasks that support the security plan creation process.
These prompts are heavily inspired by the Edge AI Accelerator project and their use of Hyper velocity engineering.
- Open the prompt you want to use in the
/.github/promptsdirectory. - Choose a model that has reasoning and planning capabilities, such as
gpt-4oorClaude Sonnet 4. - Provide the prompt with a simple command like
Use the instructions and generate me the document. Ask clarifying questions where you see fit.
The following prompts are available to support the security plan creation workflow:
mermaid-diagram-creator.prompt.md: Analyzes images and creates corresponding Mermaid diagrams. To use this prompt, add the image as additional context to the prompt.prompt-new.prompt.md: Creates prompt/instruction files based on source code or user-provided files, analyzing coding standards and conventions.prompt-refactor.prompt.md: Refactors existing prompt/instruction files to improve clarity, organization, and effectiveness while maintaining their original purpose.
If you have suggestions for improving the chat mode or supporting prompts, please feel free to open an issue or submit a pull request. Your contributions are welcome!