Skip to main content

alpha-omega-security/threat-model

SkillsMP 已收集 alpha-omega-security/threat-model 中的 8 个 Skill。打开任一 Skill 可查看来源和详情。

最近记录的来源活动
SkillsMP 收录数据更新
已收集 skills
8
GitHub 星标
32
GitHub Forks
5

这个仓库中的 skills

1 个职业分类 · 已分类 100%

已展示 8 / 8 个已收集 Skill。

职业分类
信息安全分析师
描述

Draft phase 3.5 of a threat model from the orientation brief, surface analysis, and maintainer answers. USE WHEN writing threat-model.md to the canonical §1.1–§1.19 structure. Combines concise prose with the §1.7 trust table and contract matrix, §1.8 output…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Backtest phase 3.6 of threat-model production against historical findings before sign-off. USE WHEN a draft model must prove it can uniquely route real reports. Builds a stratified producer-side corpus across components and contract dimensions, clusters large…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Emit and validate the §1.19 machine-readable companions: threat-model.yaml using schema threat-model-sidecar/v2, and the flat threat-model.json export conforming to schema.json. USE WHEN an orchestrated threat model is ready for publication, automated or…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Produce a threat model for a targeted open-source repository or package: its implicit security contract (assumptions, guarantees, disclaimed properties, and known misuses), not an audit, pentest, CVE list, or build-hygiene review. USE WHEN asked to produce,…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Triage one inbound vulnerability report, scanner hit, fuzzer artifact, or AI finding against a finished threat model. USE WHEN asked whether a finding is valid or in scope. Applies the §1.1 routing algorithm and §1.17 precedence to assign exactly one closed…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Run phase 3.4 maintainer question waves for threat-model production. USE WHEN inferred claims need ratification or interview-first versus draft-first mode must be chosen. Asks 3–7 prioritized proposed-answer questions per wave; wave 1 always covers scope,…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Orient and mine an open-source repository for threat-model production phases 3.1–3.2. USE WHEN starting a threat model or surveying security posture before modeling. Reads README, top-level docs, SECURITY/THREAT docs, maintainer issue rulings, and changelog…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Perform phase 3.3 deep analysis of an in-scope attack surface for a threat model. USE WHEN the orientation brief is ready and code must be read to derive the §1.7 per-input trust table and contract-dimension matrix, §1.5 no-surprise side-effects inventory,…

原文语言:英语

更新
已展示 8 / 8 个已收集 Skill。