← ClaudeAtlas

threat-model-privacylisted

Conducts structured IC-methodology personal and project-level privacy threat modeling. Produces adversary profiles, asset inventories, attack surface maps, confidence-graded risk assessments, and tiered mitigation plans. Use when user says "threat model", "model my threats", "what are my risks", "who would target me", "privacy risk assessment", "OPSEC plan", "am I a target", "what should I be protecting", "security posture review", or when starting a new project, identity, or operational context that warrants a structured risk baseline. Also triggers for relationship-context threat modeling (stalking, coercive control, harassment scenarios).
fevra-dev/Subrosa · ★ 0 · AI & Automation · score 72
Install: claude install-skill fevra-dev/Subrosa
# Threat Model: Privacy Structured adversarial analysis of personal and project-level privacy risk. Produces a defensible, falsifiable threat model using IC-standard analytic methodology. **Invoke `opsec-review`** to audit specific artifacts once the threat model is established. **Invoke `redact`** to sanitize content identified as exposed by this model. **Regulatory grounding:** when a threat model touches statutory exposure — breach-notification clocks, regulator powers, penalty ceilings, cross-border compulsion — pull jurisdiction facts from `taxonomy/regulatory-taxonomy.md` and its records (axes A1/A8/A10) rather than restating them; cross-regime incompatibilities live in `taxonomy/regulatory-taxonomy--conflicts.md`. Relevant to the INSTITUTIONAL capability class and Archetypes 6–7. --- ## Methodology Four-phase IC-influenced process: ``` Phase 1: ASSET INVENTORY — What are you protecting? Phase 2: ADVERSARY PROFILING — Who wants it and why? Phase 3: ATTACK SURFACE MAP — How could they get it? Phase 4: MITIGATION PLAN — What do you do about it? ``` Analytic standards applied throughout: - **Falsification-first**: every claim must state what evidence would disprove it - **ICD 203 confidence framing**: four-dimensional confidence on all risk assessments (source quality, analytic soundness, information completeness, analytic consistency) - **Pre-mortem discipline**: for each HIGH+ risk, ask "assume this was exploited — what happened?" - **Adversarial pressur