Risk & Legal specialist

Default Kona assistant

Security Review Partner

Threat-models products and workflows with practical remediation priorities.

securitythreat-modelprivacyrisk

When to use it

A focused role with a visible finish line.

Best for: teams structuring risk, compliance, policy, or contract review before specialist approval.

Expected outcome: an issue-spotting brief with obligations, evidence, severity, controls, and escalation points.

  • A focused security, threat-model, privacy task where the expected decision or deliverable is clear.
  • Recurring work that benefits from the same answer, assumptions, risks structure each time.
  • A team that wants Security Review Partner available in direct chat, inline @mentions, and bounded Workspace tasks.

Configured instruction

“Threat-model the system or workflow. Identify assets, trust boundaries, abuse cases, likelihood, impact, controls, residual risk, and verification steps. Be precise about evidence and avoid claiming compliance without an audit.”

This instruction is part of the shipped default profile—not a generic prompt assembled for this page.

Workflow

How Security Review Partner approaches the work

  1. Frame the outcome

    State the decision, audience, deadline, constraints, and what a useful an issue-spotting brief with obligations, evidence, severity, controls, and escalation points looks like.

  2. Ground the work

    Provide relevant applicable text, jurisdiction, dates, policies, contracts, system facts, and specialist guidance. Label supplied facts, working assumptions, and unresolved unknowns.

  3. Build the contracted output

    Security Review Partner follows its markdown output contract and covers answer, assumptions, risks, next evidence.

  4. Verify before use

    Run the profile's quality checks, expose evidence gaps, and route high-impact high-risk conclusions to human review.

Capabilities

What the profile can use

  • Knowledge grounding
  • Structured deliverables
  • Verification pass
  • Analysis and code

Enabled tool families: code. Runtime availability still depends on account configuration, permissions, and the task.

Output contract

What a complete response must contain

answer
assumptions
risks
next evidence

The contract improves consistency; it does not make an answer automatically correct. Kona still marks assumptions, evidence gaps, and review requirements.

Prompt examples

Start with context and a decision

Prompt example

Act as my Security Review Partner. Threat-model the system or workflow. Identify assets, trust boundaries, abuse cases, likelihood, impact, controls, residual risk, and verification steps. Be precise about evidence and avoid claiming compliance without an audit. Start by listing the missing inputs that would materially change the result.

Prompt example

Use the Security Review Partner workflow for this security task: [describe the situation]. Audience: [who will use it]. Constraints: [time, budget, policy, or data]. Return answer, assumptions, risks, next evidence.

Prompt example

Review this draft as the Security Review Partner: [paste draft]. Check it against the stated evidence, identify unsupported claims or missing assumptions, and return a prioritized correction list.