agentsclimarketplace

Cybersecurity risk assessor

Skill a5c-ai/babysitter/library/specializations/domains/science/biomedical-engineering/skills/cybersecurity-risk-assessor

Medical device cybersecurity risk assessment skill per FDA premarket and postmarket guidanceFrom its SKILL.md

Install
npx -y skills add a5c-ai/babysitter --skill cybersecurity-risk-assessor

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

SKILL.md

2.9 KB, 502 tokens by cl100k_base, as published. Nobody here has run it

Cybersecurity Risk Assessor Skill

Purpose

The Cybersecurity Risk Assessor Skill evaluates cybersecurity risks for medical devices per FDA guidance and IEC 81001-5-1, supporting threat modeling, vulnerability assessment, and security control implementation.

Capabilities

  • Threat modeling (STRIDE methodology)
  • Vulnerability assessment
  • SBOM (Software Bill of Materials) generation
  • Security control identification
  • Penetration testing planning
  • Cybersecurity documentation for FDA submissions
  • Attack surface analysis
  • Security architecture review
  • Coordinated vulnerability disclosure planning
  • Postmarket cybersecurity management
  • Patch management planning

Usage Guidelines

When to Use

  • Assessing device cybersecurity risks
  • Planning penetration testing
  • Preparing FDA cybersecurity submissions
  • Managing software dependencies

Prerequisites

  • Software architecture documented
  • Network connectivity defined
  • Data flows identified
  • Third-party components cataloged

Best Practices

  • Integrate cybersecurity from design inception
  • Maintain current SBOM
  • Plan for security updates throughout lifecycle
  • Establish vulnerability disclosure process

Process Integration

This skill integrates with the following processes:

  • Software Development Lifecycle (IEC 62304)
  • Medical Device Risk Management (ISO 14971)
  • 510(k) Premarket Submission Preparation
  • Post-Market Surveillance System Implementation

Dependencies

  • FDA Cybersecurity guidance
  • IEC 81001-5-1 standard
  • SBOM tools (CycloneDX, SPDX)
  • Vulnerability databases (NVD, CVE)
  • Threat modeling frameworks

Configuration

cybersecurity-risk-assessor:
  threat-methodologies:
    - STRIDE
    - PASTA
    - attack-trees
  sbom-formats:
    - CycloneDX
    - SPDX
  security-tiers:
    - Tier-1-higher
    - Tier-2-standard
  control-frameworks:
    - NIST-CSF
    - IEC-62443

Output Artifacts

  • Threat models
  • Vulnerability assessments
  • SBOM documents
  • Security architecture documents
  • Penetration test plans
  • FDA cybersecurity submissions
  • Security control matrices
  • Patch management plans

Quality Criteria

  • All threat vectors identified
  • Vulnerabilities assessed with CVSS scores
  • SBOM is complete and current
  • Security controls address identified risks
  • Documentation meets FDA requirements
  • Postmarket security plan established

What ships with it

Read from the repository

Just SKILL.md. No reference files, no scripts.

Keep looking

Skills are one crate of 326,059. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.