IC

icdev-boundary

Evaluates the impact of requirement changes on ATO boundaries and analyzes supply chain risks for system components.

Install

mkdir -p .claude/skills/icdev-boundary && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/19036" && unzip -o skill.zip -d .claude/skills/icdev-boundary && rm skill.zip

Installs to .claude/skills/icdev-boundary

Activation

This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.

Assess ATO boundary impact and manage supply chain risk for requirements. Use when analyzing how a requirement change affects the ATO boundary or supply chain.
159 chars✓ has a “when” trigger
Advanced

Key capabilities

  • Assess ATO boundary impact for requirements
  • Generate alternative COAs for RED-tier requirements
  • Build dependency graphs for vendor supply chains
  • Perform SCRM assessment across NIST 800-161 dimensions
  • Check ISA/MOU lifecycle and flag overdue reviews
  • Triage vulnerabilities with blast radius propagation

How it works

The skill runs RICOAS Phase 2, which involves evaluating requirements against ATO boundaries, generating alternatives, building supply chain dependency graphs, scoring vendors, checking agreements, and triaging CVEs.

Inputs & outputs

You give it
Project ID, requirement ID, system ID, and optional flags for SCRM, ISA, or CVE checks
You get back
CUI-marked output with boundary impact assessment, alternative COAs, vendor scores, agreement statuses, and CVE triage results

When to use icdev-boundary

  • Assessing requirement change impact
  • Auditing vendor supply chain risk
  • Managing ATO boundary compliance
  • Triaging CVEs in dependency trees

About this skill

/icdev-boundary — ATO Boundary & Supply Chain Analysis

Usage

/icdev-boundary <project-id> [--assess <requirement-id> --system <system-id>] [--scrm] [--isa-check] [--cve-check]

What This Does

Runs RICOAS Phase 2 — ATO boundary impact and supply chain intelligence:

  1. Assess boundary impact — evaluate how requirements affect existing ATO boundaries (GREEN/YELLOW/ORANGE/RED)
  2. Generate alternatives — for RED-tier requirements, produce 3-5 alternative COAs within existing ATO
  3. Build dependency graph — track vendor supply chain with upstream/downstream relationships
  4. SCRM assessment — score vendors across 6 NIST 800-161 dimensions, check Section 889
  5. ISA/MOU lifecycle — check expiring agreements, flag overdue reviews
  6. CVE triage — triage vulnerabilities with blast radius propagation through dependency graph

All operations produce CUI-marked output and record audit trail entries.

See REFERENCE.md for step-by-step commands (Steps 1–8).

Error Handling

  • If ATO system not registered: prompt to register before assessment
  • If requirement not found: check intake session, report error
  • If dependency graph empty: suggest adding vendors via add_vendor
  • If SCRM assessment fails: check vendor records exist
  • If CVE propagation finds circular dependency: break cycle, report warning

Security Gates

  • RED-tier requirement without alternative COA → blocks
  • Critical SCRM risk unmitigated → blocks
  • ISA expired with active data flow → blocks
  • Critical CVE SLA overdue → blocks
  • Section 889 prohibited vendor detected → blocks

Related Skills

  • /icdev-intake — Requirements intake (Phase 1 feeds boundary assessment)
  • /icdev-comply — Compliance artifacts (SSP addendum for YELLOW/ORANGE tiers)
  • /icdev-maintain — Maintenance audit (CVE triage feeds maintenance workflow)
  • /icdev-secure — Security scanning (vulnerability data feeds CVE triage)

When not to use it

  • If ATO system is not registered
  • If requirement is not found in intake session
  • If dependency graph is empty and vendors are not added

Limitations

  • RED-tier requirement without alternative COA blocks
  • Critical SCRM risk unmitigated blocks
  • ISA expired with active data flow blocks

How it compares

This skill provides a structured, automated approach to ATO boundary impact and supply chain risk analysis, including security gates and related skill integrations, which is more complete than manual assessments.

Compared to similar skills

icdev-boundary side by side with the closest alternatives in the catalog.

SkillInstallsUpdatedSafetyDifficulty
icdev-boundary (this skill)029dNo flagsAdvanced
performing-windows-artifact-analysis-with-eric-zimmerman-tools02moReviewAdvanced
qa-tester298moNo flagsIntermediate
protocol-reverse-engineering96moReviewAdvanced

Try saying

Example prompts that trigger this skill in your AI assistant.

You might also like

performing-windows-artifact-analysis-with-eric-zimmerman-tools

xtofuub

Perform comprehensive Windows forensic artifact analysis using Eric Zimmerman's open-source EZ Tools suite including

00

qa-tester

svilupp

Browser automation QA testing skill. Systematically tests web applications for functionality, security, and usability issues. Reports findings by severity (CRITICAL/HIGH/MEDIUM/LOW) with immediate alerts for critical failures.

29113

protocol-reverse-engineering

wshobson

Master network protocol reverse engineering including packet analysis, protocol dissection, and custom protocol documentation. Use when analyzing network traffic, understanding proprietary protocols, or debugging network communication.

973

equilateral-agents

Equilateral-AI

22 production-ready AI agents with database-driven orchestration for security reviews, code quality analysis, deployment validation, infrastructure checks, and compliance. Auto-activates for security concerns, deployment tasks, code reviews, quality checks, and compliance questions. Includes upgrade paths to enterprise features (GDPR, HIPAA, multi-account AWS, ML-based optimization).

564

qa-expert

daymade

This skill should be used when establishing comprehensive QA testing processes for any software project. Use when creating test strategies, writing test cases following Google Testing Standards, executing test plans, tracking bugs with P0-P4 classification, calculating quality metrics, or generating progress reports. Includes autonomous execution capability via master prompts and complete documentation templates for third-party QA team handoffs. Implements OWASP security testing and achieves 90% coverage targets.

1427

secops-triage

google

Expert guidance for security alert triage. Use this when the user asks to "triage" an alert or case.

424

Search skills

Search the agent skills registry