All skills
hardw00t avatar

/threat-modeling

@f9bb3b2

Systematic threat modeling skill for applications, APIs, and systems using STRIDE, PASTA, Attack Trees, DREAD, LINDDUN, and OCTAVE. Use when assessing security architecture, creating data flow diagrams (Mermaid), enumerating threats from OpenAPI specs or architecture docs, building attack trees, mapping threats to NIST/CIS/OWASP ASVS controls, or producing a threat model report. Triggers on requests to threat model, analyze attack surface, create a DFD, apply STRIDE, or design security mitigations.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/threat-modeling

This session only. Nothing lands on disk.

examplesmermaid_dfd_templates.md

≈1.1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Mermaid DFD Templates

Ready-to-adapt Mermaid templates for DFDs with trust boundaries. Frontier models render these inline in most chat surfaces.

Template 1: Level-0 Context Diagram

flowchart LR
    User([End User])
    Admin([Admin])
    ThirdParty([3rd-Party API])

    subgraph system["System Under Analysis"]
        App([Application])
    end

    Store[(Data Store)]

    User -- "HTTPS / session cookie / PII" --> App
    Admin -- "HTTPS+MFA / admin token" --> App
    App -- "TLS / app creds / PII" --> Store
    App -- "HTTPS / OAuth2" --> ThirdParty

Template 2: Classic 3-Tier Web App (Level-1)

flowchart TB
    subgraph internet[Internet - Untrusted]
        User([User Browser])
    end

    subgraph dmz["DMZ - TB1"]
        WAF([WAF])
        LB([Load Balancer])
    end

    subgraph apptier["Application Tier - TB2"]
        Web([Web Frontend])
        API([API Server])
        Worker([Async Worker])
    end

    subgraph datatier["Data Tier - TB3"]
        DB[(PostgreSQL)]
        Cache[(Redis)]
        Queue[(RabbitMQ)]
        Blob[(S3)]
    end

    subgraph external[Partner Trust Zone]
        Stripe([Stripe])
        Email([SES])
    end

    User -->|HTTPS| WAF
    WAF --> LB
    LB -->|HTTPS| Web
    Web -->|HTTPS+JWT| API
    API -->|TLS+creds| DB
    API -->|TLS| Cache
    API -->|AMQPS| Queue
    API -->|HTTPS+SigV4| Blob
    Queue --> Worker
    Worker -->|TLS+creds| DB
    Worker -->|HTTPS+OAuth2| Stripe
    Worker -->|HTTPS+SigV4| Email

Template 3: Microservices with Service Mesh

flowchart TB
    subgraph edge[Edge]
        Gateway([API Gateway])
    end

    subgraph mesh["Service Mesh - mTLS between all"]
        Auth([auth-svc])
        Users([users-svc])
        Orders([orders-svc])
        Payments([payments-svc])
        Notifier([notifier-svc])
    end

    subgraph data[Data Tier]
        AuthDB[(auth-db)]
        UsersDB[(users-db)]
        OrdersDB[(orders-db)]
        Bus[(Kafka)]
    end

    Client([Client]) -->|HTTPS+JWT| Gateway
    Gateway -->|mTLS| Auth
    Gateway -->|mTLS| Users
    Gateway -->|mTLS| Orders
    Auth -->|TLS| AuthDB
    Users -->|TLS| UsersDB
    Orders -->|TLS| OrdersDB
    Orders -->|mTLS| Payments
    Orders -->|TLS+SASL_SSL| Bus
    Bus --> Notifier

Template 4: Mobile App + Backend

flowchart LR
    subgraph device["Mobile Device - Untrusted"]
        App([Mobile App])
        Keychain[(Keychain/Keystore)]
    end

    subgraph edge["Backend Edge - TB1"]
        Gateway([API Gateway])
    end

    subgraph backend["Backend - TB2"]
        Auth([Auth Service])
        API([API])
    end

    DB[(Primary DB)]

    App -->|HTTPS + Cert Pinning + OAuth2| Gateway
    App <-->|secure enclave| Keychain
    Gateway -->|mTLS| Auth
    Gateway -->|mTLS| API
    Auth -->|TLS| DB
    API -->|TLS| DB

Template 5: IoT / Edge

flowchart LR
    subgraph field[Field - Physically Untrusted]
        Device([IoT Device])
        GW([Edge Gateway])
    end

    subgraph cloud[Cloud Backend]
        Ingest([Ingest Service])
        Stream([Stream Processor])
        TS[(Time-Series DB)]
    end

    Device -->|MQTT+TLS+device cert| GW
    GW -->|AMQPS+mTLS| Ingest
    Ingest --> Stream
    Stream --> TS

Template 6: AI/ML Inference Pipeline

flowchart LR
    User([User]) -->|HTTPS+JWT| API([API])
    API -->|TLS| Orchestrator([Orchestrator])
    Orchestrator -->|HTTPS+API key| LLM([External LLM Provider])
    Orchestrator -->|TLS| VectorDB[(Vector Store)]
    Orchestrator -->|TLS| Cache[(Prompt Cache)]
    Orchestrator --> Logger[(Audit Log - append-only)]

    subgraph trust["Untrusted Inputs"]
        UserInput([User Prompts])
        Docs([Retrieved Docs])
    end

    UserInput -.-> API
    Docs -.-> Orchestrator

Styling Tips

Add colour to highlight trust zones:

flowchart LR
    classDef untrusted fill:#fee,stroke:#c33
    classDef trusted fill:#efe,stroke:#3c3
    classDef external fill:#fef,stroke:#93c

    User([User]):::untrusted
    App([App]):::trusted
    Stripe([Stripe]):::external
    User --> App --> Stripe

Conventions in These Templates

  • Rectangles = external entities (User, Admin)
  • Rounded rectangles / stadiums (([Name])) = processes
  • Cylinders ([(Name)]) = data stores
  • Subgraphs = trust boundaries — name them "<Zone Name> - TB<N>"
  • Edge labels = protocol / auth / data classification

Source: SKILL.md on GitHub

No alerts16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The skill is safe. It consists entirely of markdown documentation, templates, and workflows for threat modeling methodologies (such as STRIDE, PASTA, and LINDDUN) to guide AI agent security reviews. It contains no executable code or scripts, and no malicious patterns were detected.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    1/1 file flagged

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/threat-modeling