Inspect the team before use
Active database publicationCybersecurity Assurance
Read-only threat, control, and incident-readiness analysis joined into an evidence-backed security assurance register.
Opens the installed OpenCorvus desktop app. The client re-downloads and re-verifies this exact revision, then asks you for an install scope. No desktop app yet? Install OpenCorvus first
Bound execution graph
Workflow and handoffs
The graph shows who owns each step and which earlier result it depends on. It explains the team's collaboration contract; it is not live task progress and does not schedule Agents from the page.
9a93fcd54 nodes- 01security-threat-evidence-analystMaps threats and observed evidence.
root - 02security-control-coverage-analystMaps control coverage and gaps.
root - 03security-incident-readiness-analystMaps incident readiness evidence.
root - 04security-assurance-integratorJoins all branches into the assurance register.
← security-control-coverage-analyst + security-incident-readiness-analyst + security-threat-evidence-analyst
Intended scope
Use for bounded security posture, control evidence, and incident-readiness assurance.
- Product pillarscode + work
- Agent roster4 declared roles
- Declared workflows1 complete responsibility and dependency graphs
- Full capability projection1 Skills · 3 tools · 0 MCP refs
Roles and ownership
This roster comes from the exact package. Agent identity and base role participate in the real runtime; avatars, ratings, and personas do not influence selection.
- Threat Evidence Analyst
exploreMaps assets, trust boundaries, threat claims, and observed evidence. - Control Coverage Analyst
delegated-workerMaps claimed controls to evidence, owners, gaps, and verification status. - Incident Readiness Analyst
delegated-workerAssesses detection, escalation, containment, recovery, and exercise evidence. - Security Assurance Integrator
delegated-workerJoins all security evidence into one reviewable assurance register.
Workflow and handoffs
The graph shows who owns each step and which earlier result it depends on. It explains the team's collaboration contract; it is not live task progress and does not schedule Agents from the page.
security-assurance-pack
Security Assurance Pack
Three independent assurance branches converge into one accountable evidence register.
- 01security-threat-evidence-analystMaps threats and observed evidence.depends_on: []
- 02security-control-coverage-analystMaps control coverage and gaps.depends_on: []
- 03security-incident-readiness-analystMaps incident readiness evidence.depends_on: []
- 04security-assurance-integratorJoins all branches into the assurance register.depends_on: security-control-coverage-analyst, security-incident-readiness-analyst, security-threat-evidence-analyst
Capability scope
The full projection includes built-in, default, and package-owned references. The package-owned subset is disclosed separately and never presented as the complete permission surface.
- Full Skill projection1 unique references; 1 are the package-owned subset
- Full tool projection3 unique references; 0 are the package-owned subset
- Full MCP projection0 server/tool/prompt/resource references; 0 are the package-owned subset
- Configuration0 fields · 0 required
Version and provenance
During publication import, the website reconstructs the canonical file tree and complete display facts from the exact ZIP referenced by the signed catalog. The local Manager validates shape, identity, topology, and digest again during install.
- Identitybuiltin/cybersecurity-assurance
- Version2026.08.13.1
- Package SHA-2569a93fcd57d046a081b1e23f3221c70fddc6d8faed63560ec0860552d8b2dd32b
This record belongs to the active database publication. The importer checked it field by field against the OpenCorvus-signed catalog, exact ZIP, and content digest. The signing private key never reaches the production server; third-party publisher identity and independent review services are not open yet.
Install boundary
The page can hand this exact revision to an installed OpenCorvus client, or stream its content-addressed ZIP. Neither path installs or activates a team from the web: the client re-downloads the archive, re-verifies its bytes, digest, and shape, and requires an explicit scope.
- 01Resolve the exact revision in the website database, verify ZIP bytes and SHA-256, then hand it to the client or start the download response
- 02Recompute the digest and strictly validate the selected package during client import
- 03Require the operator to choose project or user-global scope
- 04Import atomically through the Manager and return a mutation receipt
- 05Select the installed Squad separately before the active profile changes