Skip to main content

alpha-omega-security/threat-model

SkillsMP a collecté 8 skills depuis alpha-omega-security/threat-model. Ouvrez un skill pour examiner sa source et ses détails.

Dernière activité source enregistrée
Catalogue SkillsMP mis à jour
skills collectés
8
Étoiles GitHub
32
Forks GitHub
5

Skills dans ce dépôt

1 catégories métier · 100% classifié

Affichage de 8 skills collectés sur 8.

métier
Analystes en sécurité de l'information
description

Draft phase 3.5 of a threat model from the orientation brief, surface analysis, and maintainer answers. USE WHEN writing threat-model.md to the canonical §1.1–§1.19 structure. Combines concise prose with the §1.7 trust table and contract matrix, §1.8 output…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Backtest phase 3.6 of threat-model production against historical findings before sign-off. USE WHEN a draft model must prove it can uniquely route real reports. Builds a stratified producer-side corpus across components and contract dimensions, clusters large…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Emit and validate the §1.19 machine-readable companions: threat-model.yaml using schema threat-model-sidecar/v2, and the flat threat-model.json export conforming to schema.json. USE WHEN an orchestrated threat model is ready for publication, automated or…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Produce a threat model for a targeted open-source repository or package: its implicit security contract (assumptions, guarantees, disclaimed properties, and known misuses), not an audit, pentest, CVE list, or build-hygiene review. USE WHEN asked to produce,…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Triage one inbound vulnerability report, scanner hit, fuzzer artifact, or AI finding against a finished threat model. USE WHEN asked whether a finding is valid or in scope. Applies the §1.1 routing algorithm and §1.17 precedence to assign exactly one closed…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Run phase 3.4 maintainer question waves for threat-model production. USE WHEN inferred claims need ratification or interview-first versus draft-first mode must be chosen. Asks 3–7 prioritized proposed-answer questions per wave; wave 1 always covers scope,…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Orient and mine an open-source repository for threat-model production phases 3.1–3.2. USE WHEN starting a threat model or surveying security posture before modeling. Reads README, top-level docs, SECURITY/THREAT docs, maintainer issue rulings, and changelog…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Perform phase 3.3 deep analysis of an in-scope attack surface for a threat model. USE WHEN the orientation brief is ready and code must be read to derive the §1.7 per-input trust table and contract-dimension matrix, §1.5 no-surprise side-effects inventory,…

Langue du texte source : anglais

mis à jour
Affichage de 8 skills collectés sur 8.