Skip to content

akoita/security

v0.5.4

Project-agnostic security skills for repository audits, diff review, deterministic scanning, supply chain, threat modeling, smart contracts, and AI systems.

security-threat-model

Build a repository-grounded threat model: extract the system model from the code, derive trust boundaries, assets and entry points, calibrate attacker capabilities, enumerate abuse paths, rank them by likelihood and impact, and separate existing mitigations from recommended ones. Use for threat modeling, attack surface analysis, trust boundary review, abuse path enumeration, STRIDE or LINDDUN design review, and model-as-code with pytm or threagile, including systems that contain AI agents. Do not use to find concrete vulnerabilities in code (use security-audit for a repository audit or security-review for a diff), to run scanners (use security-scan), or for the detailed LLM, agent, and MCP control checklists (use security-ai).

Read SKILL.md at the source

Pinned to revision 6335fa80c2f6, so it is the text this page describes rather than whatever the author pushed since.

Files

Every link opens the file at its source, pinned to the revision this page describes.