All skills
bitwarden avatar

/threat-modeling

@d5bc17c official
by bitwardenbitwarden/ai-plugins155 stars
20

This skill should be used when the user asks to "create a threat model", "define security goals", "generate a data flow diagram", "write security definitions", "perform an initial security assessment", or needs to produce threat model artifacts for new features or architecture changes.

Use this Skill: https://skilld.dev/gh/bitwarden/ai-plugins/threat-modeling

This session only. Nothing lands on disk.

referencessecurity-principles.md

≈1.2k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Bitwarden Security Principles (P01-P06)

These six principles form the foundation for all threat modeling at Bitwarden. Reference them when writing security goals and evaluating threats.

Sourced from Security Principles.

Principles

Principle Name Core Guarantee
P01 Servers are Zero Knowledge Bitwarden infrastructure cannot access unencrypted user data. The server must not enable weakening of user-chosen protections, masquerade server data as user-encrypted content, or access encrypted data outside the client context.
P02 A Locked Vault is Secure Highly sensitive vault data cannot be accessed in plaintext once the vault is locked, even if the device is compromised after locking. Platform limitations (e.g., JS memory) are mitigated through buffer clearing and available security features.
P03 Limited Security on Semi-Compromised Devices For unlocked vaults on devices with userspace malware (but intact OS/kernel), clients maximize kernel/OS-level protections and balance security with usability through controls like biometrics.
P04 No Security on Fully Compromised Systems Bitwarden cannot guarantee vault protection when hardware or OS-level integrity is fully compromised. This applies to unlocked vaults only — locked vaults are covered by P02.
P05 Controlled Access to Vault Data Vault data, whether at rest or in use, is accessible only to authorized parties under the user's explicit control. Isolation mechanisms are critical in high-risk environments like web browsers.
P06 Minimized Impact of Security Breaches Limit breach scope and duration through session invalidation, key rotation (countering "harvest now, decrypt later"), and post-compromise security (new data remains protected after a breach).

Controlled Exceptions

Principles have documented exceptions. When threat modeling, check the full principles documentation for current exceptions.

Known examples:

  • P01 — Key Connector: Self-hosted SSO without passwords. The server holds encryption keys on behalf of the user.
  • P01 — Icons Service: Plaintext domain names are sent to retrieve favicons.

Security Requirements

Security requirements define concrete MUST/SHOULD/MAY obligations organized by category. Reference these when validating that a design satisfies Bitwarden's security standards.

Full requirements: Security Requirements

Category Scope Key Obligations
VD Vault Data Protected at rest (encrypted with UserKey), allowed in use (decrypted during unlock), trusted channels in transit, export requires informed consent
EK Encryption Keys 256-bit security strength, protected at rest and in transit, must never be exported
AT Authentication Tokens Protected storage at rest, mandatory transit protection
SC Secure Channels Confidentiality, integrity, replay prevention, forward secrecy for long-lived channels
TC Trusted Channels Secure channel properties plus receiver identity verification

Source: SKILL.md on GitHub

No alerts14d3 checks · Risk SAFE
  • Gen Agent Trust Hub14d

    The threat-modeling skill is a documentation-focused framework for performing security assessments using Bitwarden's internal standards. It adheres to secure coding practices and Bitwarden's security principles, posing no risk of code execution, data exfiltration, or malicious persistence.

  • Socket14d

    No alerts

  • Snyk14d

    Risk: LOW · No issues

Signed by skilld at d5bc17c. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
  • Security
  • threat-modeling
  • stride
  • data-flow-diagrams
  • security-definitions
  • architecture
  • appsec
  • risk-assessment

README badge

README badge for bitwarden/ai-plugins/threat-modeling

Guides engineering teams through creating threat models, data flow diagrams, and security definitions for new features or architecture changes using Bitwarden's 4-phase engagement model. Focuses on Phase 1 activities (STRIDE-based threat identification, security goal definition) and provides templates for documenting attacker capabilities, security guarantees, and current implementation gaps.

Generated from the current SKILL.md.

Does this skill generate STRIDE threat models?
The skill uses STRIDE as a framework for structured threat identification during Phase 1 (Initial Security Assessment), but its primary output is Bitwarden's Security Definitions format, which combines threat model, security goals, and accepted goal status into a single construct.
Can this skill work with existing systems or only new features?
The skill supports both greenfield projects and architecture changes. It is designed for Phase 1 (engineering-owned initial assessment) and can assist with threat modeling for new features, services, or modifications to data sharing and IPC channels.
When should I involve the AppSec team using this skill?
Perform an Initial Security Assessment using this skill first. Escalate to AppSec (#team-eng-appsec) for greenfield projects, data sharing modifications, new IPC channels, cross-domain functionality, or if you are uncertain about security implications after assessment.
What artifact formats does this skill produce?
The skill generates Security Definition documents (markdown), data flow diagrams (Mermaid, Excalidraw, or Structurizr), and threat catalogs with mitigation tracking. Templates are provided for each artifact type.
Does this skill create security definitions aligned with specific principles?
Yes. Security goals must align with Bitwarden's security principles (P01–P06), and each goal requires a rationale stating which principle it enforces, what asset it protects, and the user-visible harm if violated.

Generated from the current SKILL.md. These answers refresh after source changes.