一键导入
security-threat-model
Sandbox, LLM/tool trust boundaries, red-team tests, metrics/docs coupling, and threat-model update triggers.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
Sandbox, LLM/tool trust boundaries, red-team tests, metrics/docs coupling, and threat-model update triggers.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
Process Forgejo PR feedback with reflection, guardrail-gap classification, and inline thread replies.
Fine-grained outside-in RED-GREEN-REFACTOR microcycles with specialist agents and single-diagnostic implementation.
UI-first BDD for event-model slices, RGR sequence, observed-failure evidence, drill-down unit tests, and non-behavioral exemptions for eddy.
Write implementation plans as test-addressed red-green-refactor cycles, with UI-first Cucumber REDs for event-model slices, rather than component waterfalls.
eddy Rust workspace conventions, Nix toolchain use, error handling, env parsing, tests, and docs coupling.
Event Modeling pattern advice; use when deciding whether something is an event, command, read model, state change, state view, automation, or translation.
| name | security-threat-model |
| description | Sandbox, LLM/tool trust boundaries, red-team tests, metrics/docs coupling, and threat-model update triggers. |
Use this skill when changes touch webhooks, sandboxing, tool execution, LLM inputs or outputs, secrets, dependencies, auth, metrics, or deployment.
Read docs/THREAT-MODEL.md and the relevant ADRs before changing security-sensitive behavior.
ar-sandbox?If a documented threat changes, update the matching red-team test when needed. Metrics changes may require updates to Prometheus rules, Grafana dashboards, and contract tests.