security-threat-model - Repository-grounded threat modeling for source code
Enumerates trust boundaries, assets, capabilities, abuse paths, and mitigations to write a concise Markdown threat model.
Tags
Updated: 2026-09-16Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Extract system model from codebase
- Derive trust boundaries and entrypoints
- Calibrate assets and attacker capabilities
- Enumerate threat abuse paths
- Prioritize risk likelihood and impact
- Validate assumptions with user
- Recommend targeted mitigations
- Generate Markdown threat model file
Inputs
- Repository root path
- In-scope directory paths
- Prompt template reference file
- Security controls reference file
Outputs
- Markdown threat model report file
