ワンクリックで
security-threat-model
Sandbox, LLM/tool trust boundaries, red-team tests, metrics/docs coupling, and threat-model update triggers.
Codex または Claude でインストール この Prompt をコピーして Codex、Claude、または他のアシスタントに貼り付けると、Skill ページを確認してインストールできます。
メニュー
Sandbox, LLM/tool trust boundaries, red-team tests, metrics/docs coupling, and threat-model update triggers.
Codex または Claude でインストール この Prompt をコピーして Codex、Claude、または他のアシスタントに貼り付けると、Skill ページを確認してインストールできます。
SOC 職業分類に基づく
Process Forgejo PR feedback with reflection, guardrail-gap classification, and inline thread replies.
Fine-grained outside-in RED-GREEN-REFACTOR microcycles with specialist agents and single-diagnostic implementation.
UI-first BDD for event-model slices, RGR sequence, observed-failure evidence, drill-down unit tests, and non-behavioral exemptions for eddy.
Write implementation plans as test-addressed red-green-refactor cycles, with UI-first Cucumber REDs for event-model slices, rather than component waterfalls.
eddy Rust workspace conventions, Nix toolchain use, error handling, env parsing, tests, and docs coupling.
Event Modeling pattern advice; use when deciding whether something is an event, command, read model, state change, state view, automation, or translation.
| name | security-threat-model |
| description | Sandbox, LLM/tool trust boundaries, red-team tests, metrics/docs coupling, and threat-model update triggers. |
Use this skill when changes touch webhooks, sandboxing, tool execution, LLM inputs or outputs, secrets, dependencies, auth, metrics, or deployment.
Read docs/THREAT-MODEL.md and the relevant ADRs before changing security-sensitive behavior.
ar-sandbox?If a documented threat changes, update the matching red-team test when needed. Metrics changes may require updates to Prometheus rules, Grafana dashboards, and contract tests.