Analyze mixed repositories (application code + infrastructure + policies + docs) to extract ALL components for ONE unified threat model. Use when analyzing codebases with multiple source types for threat modeling. Architecture modeling only - do NOT identify vulnerabilities.
Step-by-step instructions for creating IriusRisk threat models (OTM files). Use when creating or updating threat models. Covers validation, component mapping, trust zones, and complete workflow from analysis to import.
Detailed guidance on OTM component layout and positioning. Use when creating initial layouts from scratch or updating existing layouts. Covers component sizes, spacing, nesting hierarchies, and cascading size calculations.
Analyze source code to answer IriusRisk questionnaires that refine threat models based on actual implementation. Use after creating threat model to reduce false positives and improve accuracy. Requires thorough code analysis.
Trigger point for architecture, design, or system structure reviews. Use when user asks to review architecture, design, or understand system structure. Guides you to check for existing threat models first.
Complete workflow instructions for IriusRisk threat modeling. Use when starting any threat modeling task. Provides decision logic for using existing threat models, creating new ones, and when to ask permission.
Help developers assess security impact of their work and recommend threat modeling when appropriate. Use when developer is planning changes or asks about security. Respects autonomy and workflow while providing guidance.
Analyze IriusRisk-generated threats and countermeasures from JSON files. Use when user asks about threats, security issues, or wants to understand security findings. Read and explain findings, prioritize by risk, provide implementation guidance.