Nash
Persona
Runs security operations autonomously — STRIDE threat models, CVE triage protocol, and IR runbooks
About
You are running security work in reactive bursts instead of as a system. Before releases, you are manually searching CVEs, skimming scanner output, and guessing what actually matters. During sprints, threat modeling gets skipped because nobody owns it end to end. You have tried checklist-driven reviews and one-off audits, but credentials still leak into repos, risky defaults ship to production, and incident docs are incomplete when an outage hits. Nash is an autonomous cybersecurity advisor for product and engineering teams. It was built from 200+ real security reviews across SaaS, fintech, and healthcare delivery environments, with triage patterns extracted from recurring production failures. Nash runs STRIDE threat models by default, maps findings to MITRE ATT&CK techniques when needed, and translates CVEs into stack-specific remediation tasks with owner and deadline fields. Its decision logic prioritizes exploitability, blast radius, and fix complexity in that order, because high CVSS alone does not predict business risk. Unlike generic security assistants, Nash refuses to assign a "critical" severity without a documented exploit path and an actionable remediation sequence. That anti-pattern exists because severity inflation trains teams to ignore alerts and delays real fixes. Nash also refuses checklist-only approval gates without architecture context, because controls that ignore data flow and trust boundaries miss the vulnerabilities that become incidents. What you get: SOUL.md — identity, operating constraints, and security decision rules. IDENTITY.md — communication and escalation behavior for engineering and executive audiences. THREAT_MODEL.md — STRIDE workflow with ATT&CK mapping steps. INCIDENT_RESPONSE.md — 12-scenario runbook system with escalation trees. RISK_REGISTER.md — CVSS-plus-business-impact tracking template. Requires architecture diagrams, service inventory, and an NVD or CISA KEV CVE feed.
Core Capabilities
- Generate STRIDE threat models from architecture diagrams with trust boundaries, abuse cases, and control gaps
- Triages inbound CVEs using exploitability-first scoring with KEV presence, internet exposure, and privilege context
- Map vulnerabilities to MITRE ATT&CK techniques and produce detection recommendations per tactic
- Build service-level risk registers with CVSS, business impact translation, owner assignment, and remediation deadlines
- Draft incident response decision trees for 12 security scenarios with severity thresholds and escalation paths
- Audit repositories for credential and secret leakage patterns and output rotation plus revocation playbooks
- Prioritize remediation backlogs by blast radius and fix complexity to produce sprint-ready security tickets
- Translate technical findings into executive security briefings with loss scenarios, timeline risk, and budget implications
Customer ratings
0 reviews
No ratings yet
- 5 star0
- 4 star0
- 3 star0
- 2 star0
- 1 star0
No reviews yet. Be the first buyer to share feedback.
Version History
This persona is actively maintained.
March 3, 2026
Automated deploy
One-time purchase
$69
By continuing, you agree to the Buyer Terms of Service.
Creator
Skippythemagnificent
Professional specialized agent creator for numerous industries including medical, legal, financial, and other enterprise-level applications
Taking all I've learned doing this and putting it into the creation of skills and personas to help everyone with an Openclaw.
View creator profile →Details
- Type
- Persona
- Category
- Engineering
- Price
- $69
- Version
- 1
- License
- One-time purchase
Recommended Skills
Skills that complement this persona.
Code Security Scanner
Engineering
Find hardcoded secrets, SQL injection, XSS, and command injection in any codebase. Zero dependencies.
$2
AI Prompt Injection Shield
Engineering
Stop malicious inputs from hijacking your AI agents — detect and neutralize prompt injections across every input vector
$49
tmux Coding Sessions
Engineering
Stable tmux session management for long-running AI coding agents on macOS
$5