All skills
bitwarden avatar

/threat-modeling

@d5bc17c official
by bitwardenbitwarden/ai-plugins155 stars
20

This skill should be used when the user asks to "create a threat model", "define security goals", "generate a data flow diagram", "write security definitions", "perform an initial security assessment", or needs to produce threat model artifacts for new features or architecture changes.

Use this Skill: https://skilld.dev/gh/bitwarden/ai-plugins/threat-modeling

This session only. Nothing lands on disk.

examplessecurity-definition-document.md

≈939 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Security Definition Document Template

Use this template when creating security definitions for a new feature or system.

Order Security Definitions (SDs) by Criticality descending. Reviewers anchor on what they see first — lead with the load-bearing threats.

Every Security Goal must carry a Rationale line linking the goal to a Bitwarden principle (P01–P06), the protected asset, and the user-visible harm. Goals without rationale are claims, not requirements.

When an Accepted Goal Status says a secret's exposure is "brief", "short-lived", or "transient", quantify the window — state a typical and worst-case duration. "Brief" without a number is a hope, not a status.

# [Feature Name] Security Definitions

[Link to macro-level security definitions and any parent feature documentation.]

[Optional scoping caveat, e.g., "These security definitions do not apply
in the case of a Vault Timeout set to `Never`."]

## Glossary

- **[Term]**: [Feature-specific definition]
- **[Term]**: [Feature-specific definition]

---

## SD1: [Concise threat scenario title]

**Criticality:** Critical | High | Medium | Low

### Threat Model

- Attacker can [capability]
  - An example for this is [concrete scenario]
- Attacker does not have [limitation that scopes this definition — verified against every supported OS]

### Security Goal

- [Concise, testable guarantee about what cannot happen]
- **Rationale:** Enforces [P0X: Principle Name]; protects [asset: token/key/vault data/password]; harm if violated is [user-visible consequence, e.g., "master password visible to third-party LLM provider and potentially their training pipeline"].

### Accepted Goal Status

- ✅ Goal is met:
  - [Explanation of how the goal is satisfied in the current implementation]

---

## SD2: [Concise threat scenario title]

**Criticality:** Critical | High | Medium | Low

### Threat Model

- Attacker is a **Passive Observer** — [e.g., the LLM provider receiving tool I/O, a log aggregator, a telemetry pipeline]. No malicious intent required; the harm arises from visibility during normal operation.
- Attacker does not have [limitation]

### Security Goal

- [What the system guarantees]
- **Rationale:** Enforces [P0X]; protects [asset]; harm if violated is [consequence].

### Accepted Goal Status

- Goal is **partially** met:
  - ✅ [Aspect that is satisfied]
  - ❌ [Aspect that is not satisfied — include quantified exposure window if acceptance rests on "brief" duration, e.g., "secret resides in child-process env for 1–8 s depending on KDF iterations and vault size"]

---

## SD3: [Concise threat scenario title]

**Criticality:** Critical | High | Medium | Low

### Threat Model

- Attacker can [capability]
- Attacker does not have [limitation]

### Security Goal

- [What the system guarantees]
- **Rationale:** Enforces [P0X]; protects [asset]; harm if violated is [consequence].

### Accepted Goal Status

- ❌ Goal is **not** met:
  - [Explanation of the gap. If the goal is unenforceable due to runtime constraints — e.g., memory zeroization in a GC'd, string-interning runtime — state the systemic limitation here and link any tracking issue. Do not write a goal the language cannot back.]

Before shipping

Apply the self-consistency checklist in ../references/writing-quality-sds.md:

  1. Does each goal defend against every in-scope threat-model capability?
  2. Is every goal realizable by the runtime?
  3. Is every "attacker does not have X" true on every supported OS?
  4. Is there a passive-observer SD wherever a secret crosses an external-service boundary?
  5. Is every SD tagged with Criticality, and is the document ordered Criticality-descending?

Source: SKILL.md on GitHub

No alerts14d3 checks · Risk SAFE
  • Gen Agent Trust Hub14d

    The threat-modeling skill is a documentation-focused framework for performing security assessments using Bitwarden's internal standards. It adheres to secure coding practices and Bitwarden's security principles, posing no risk of code execution, data exfiltration, or malicious persistence.

  • Socket14d

    No alerts

  • Snyk14d

    Risk: LOW · No issues

Signed by skilld at d5bc17c. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
  • Security
  • threat-modeling
  • stride
  • data-flow-diagrams
  • security-definitions
  • architecture
  • appsec
  • risk-assessment

README badge

README badge for bitwarden/ai-plugins/threat-modeling

Guides engineering teams through creating threat models, data flow diagrams, and security definitions for new features or architecture changes using Bitwarden's 4-phase engagement model. Focuses on Phase 1 activities (STRIDE-based threat identification, security goal definition) and provides templates for documenting attacker capabilities, security guarantees, and current implementation gaps.

Generated from the current SKILL.md.

Does this skill generate STRIDE threat models?
The skill uses STRIDE as a framework for structured threat identification during Phase 1 (Initial Security Assessment), but its primary output is Bitwarden's Security Definitions format, which combines threat model, security goals, and accepted goal status into a single construct.
Can this skill work with existing systems or only new features?
The skill supports both greenfield projects and architecture changes. It is designed for Phase 1 (engineering-owned initial assessment) and can assist with threat modeling for new features, services, or modifications to data sharing and IPC channels.
When should I involve the AppSec team using this skill?
Perform an Initial Security Assessment using this skill first. Escalate to AppSec (#team-eng-appsec) for greenfield projects, data sharing modifications, new IPC channels, cross-domain functionality, or if you are uncertain about security implications after assessment.
What artifact formats does this skill produce?
The skill generates Security Definition documents (markdown), data flow diagrams (Mermaid, Excalidraw, or Structurizr), and threat catalogs with mitigation tracking. Templates are provided for each artifact type.
Does this skill create security definitions aligned with specific principles?
Yes. Security goals must align with Bitwarden's security principles (P01–P06), and each goal requires a rationale stating which principle it enforces, what asset it protects, and the user-visible harm if violated.

Generated from the current SKILL.md. These answers refresh after source changes.