Skip to main content

rad-tm

Perform Rapid Developer-driven Threat Modeling (RaD-TM) on a software feature — a lightweight, six-stage method that turns a feature description, user story, design doc, API spec, or source/infrastructure code into a complete threat model: data-flow model, trust boundaries, a threat list, control mapping, severity evaluation, and a ready-to-file security backlog. Use this skill whenever the user wants to threat model a feature or system, run a security design review, identify security threats and controls, find attack surface or trust boundaries, build or update a threat model, or generate security backlog items for something they are designing or building — even if they never say "RaD-TM", "STRIDE", or "threat model" by name, and even if they just describe a feature and ask "what could go wrong here, security-wise?". Especially relevant for shift-left, feature-level reviews. Threat identification is grounded in expert-curated Threat Templates so output stays consistent and the model never invents threats.

Zur Installation springen

Quellinformationen

Repository
OWASP/www-project-rapid-developer-driven-threat-modeling
Letzte Quellaktivität
7. August 2026 um 08:08
Erkannte Sprache von SKILL.md
Englisch
Sterne
2
Forks
1

Installationsoptionen

Standardmäßig ist der Prompt ausgewählt, der zuerst die Quelle prüft. Sie können zu einem direkten Befehl wechseln oder eine lokale Kopie herunterladen.

Quelldateien prüfen

Lesen Sie SKILL.md und alle von SkillsMP angezeigten Begleitdateien, bevor Sie sich für eine Installation entscheiden.