threat-model-discipline
FeaturedUse when starting an engagement, before exploitation, or whenever the attack surface changes — build/validate the threat model and detect drift (new unreviewed surface) before advancing
Install
Quality Score: 92/100
Skill Content
Details
- Author
- hypnguyen1209
- Repository
- hypnguyen1209/offensive-claude
- Created
- 4 months ago
- Last Updated
- 5 days ago
- Language
- Python
- License
- MIT
Bundled in these plugins
Similar Skills
Semantically similar based on skill content — not just same category
threat-model
Produce a STRIDE threat model from a design doc, architecture description, or feature spec — assets and trust boundaries first, threats anchored to boundary crossings with concrete attack scenarios, severity-ranked with verifiable mitigations. Use when the user asks to threat-model a design, run a security review of an architecture, ask "how could this be attacked", or needs security sign-off input before build.
threat-modeler
Builds asset- and STRIDE-based threat models before deep security audits. Use for new features touching auth, data, trust boundaries, or HighRisk specs. Emits THREAT_MODEL. Never invents exploits or replaces security-auditor findings.
threat-model
Produce or review a STRIDE-based threat model for a system. Enumerates assets, trust boundaries, data flows, and entry points, then walks STRIDE per element to emit a threat model document with mitigations — or rates an existing model's coverage and finds gaps. Use when you need a threat model authored from an architecture/design doc or codebase, or when an existing threat model needs a coverage audit.