Skip to main content

rad-tm

Perform Rapid Developer-driven Threat Modeling (RaD-TM) on a software feature — a lightweight, six-stage method that turns a feature description, user story, design doc, API spec, or source/infrastructure code into a complete threat model: data-flow model, trust boundaries, a threat list, control mapping, severity evaluation, and a ready-to-file security backlog. Use this skill whenever the user wants to threat model a feature or system, run a security design review, identify security threats and controls, find attack surface or trust boundaries, build or update a threat model, or generate security backlog items for something they are designing or building — even if they never say "RaD-TM", "STRIDE", or "threat model" by name, and even if they just describe a feature and ask "what could go wrong here, security-wise?". Especially relevant for shift-left, feature-level reviews. Threat identification is grounded in expert-curated Threat Templates so output stays consistent and the model never invents threats.

Jump to install

Source facts

Repository
OWASP/www-project-rapid-developer-driven-threat-modeling
Last source activity
August 7, 2026 at 08:08
Detected SKILL.md language
English
Stars
2
Forks
1

Install options

The review-first prompt is selected by default. You can switch to a direct command or download a local copy.

Review the source files

Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.