security-threat-model
Use this skill for repository-grounded threat modeling that enumerates trust boundaries, assets, attacker capabilities, abuse paths, and mitigations, and writes a concise Markdown threat model. Trigger only when the user explicitly asks to threat model a codebase or path, enumerate threats/abuse paths, or perform AppSec threat modeling. Do not trigger for general architecture summaries, code review, or non-security design work.
Pinned to revision 4e4fe02df5f4, so it is the text this page describes rather than whatever the author pushed since.
Files
- skills/security-threat-model/SKILL.md
- skills/security-threat-model/LICENSE.txt
- skills/security-threat-model/agents/openai.yaml
- skills/security-threat-model/metadata.json
- skills/security-threat-model/references/prompt-template.md
- skills/security-threat-model/references/security-controls-and-assets.md
Every link opens the file at its source, pinned to the revision this page describes.