Topics
- Security
- threat-modeling
- stride
- data-flow-diagrams
- security-definitions
- architecture
- appsec
- risk-assessment
What it does
Guides engineering teams through creating threat models, data flow diagrams, and security definitions for new features or architecture changes using Bitwarden's 4-phase engagement model. Focuses on Phase 1 activities (STRIDE-based threat identification, security goal definition) and provides templates for documenting attacker capabilities, security guarantees, and current implementation gaps.
Generated from the current SKILL.md.
Frequently asked
Does this skill generate STRIDE threat models?
The skill uses STRIDE as a framework for structured threat identification during Phase 1 (Initial Security Assessment), but its primary output is Bitwarden's Security Definitions format, which combines threat model, security goals, and accepted goal status into a single construct.
Can this skill work with existing systems or only new features?
The skill supports both greenfield projects and architecture changes. It is designed for Phase 1 (engineering-owned initial assessment) and can assist with threat modeling for new features, services, or modifications to data sharing and IPC channels.
When should I involve the AppSec team using this skill?
Perform an Initial Security Assessment using this skill first. Escalate to AppSec (#team-eng-appsec) for greenfield projects, data sharing modifications, new IPC channels, cross-domain functionality, or if you are uncertain about security implications after assessment.
What artifact formats does this skill produce?
The skill generates Security Definition documents (markdown), data flow diagrams (Mermaid, Excalidraw, or Structurizr), and threat catalogs with mitigation tracking. Templates are provided for each artifact type.
Does this skill create security definitions aligned with specific principles?
Yes. Security goals must align with Bitwarden's security principles (P01–P06), and each goal requires a rationale stating which principle it enforces, what asset it protects, and the user-visible harm if violated.
Generated from the current SKILL.md. These answers refresh after source changes.