Skip to main content

security-threat-model

Build concise repository-grounded threat models covering assets, boundaries, attacker capabilities, abuse paths, and mitigations.

Datos de origen

Repositorio
Calvin-Corbett/thomas
Última actividad en el origen
9 de septiembre de 2026 a las 02:49
Idioma detectado de SKILL.md
inglés
Estrellas
4
Forks
0

Opciones de instalación

De forma predeterminada está seleccionado el prompt que primero revisa el origen. Puedes cambiar a un comando directo o descargar una copia local.

Revisa los archivos de origen

Lee SKILL.md y los archivos complementarios que muestra SkillsMP antes de decidir si quieres instalarlo.

Mostrando SKILL.md

SKILL.md
Instrucciones de origen · Vista previa de solo lectura
name
security-threat-model
description
Build concise repository-grounded threat models covering assets, boundaries, attacker capabilities, abuse paths, and mitigations.
# Security Threat Model Use this skill when the user explicitly asks for threat modeling, abuse-path analysis, or AppSec-oriented design review. ## Workflow 1. Define the system boundary, assets, and trust assumptions. 2. Enumerate attacker capabilities and likely abuse paths grounded in the actual architecture. 3. Identify mitigations, detection gaps, and residual risk. 4. Write the model in a concise structure that can drive implementation decisions. 5. Separate confirmed architecture facts from assumptions that need validation. ## Rules - Anchor the model in the real repo or system rather than abstract templates. - Keep abuse paths concrete enough to be actionable.
Ver en GitHub