All skills
hardw00t avatar

/threat-modeling

@f9bb3b2

Systematic threat modeling skill for applications, APIs, and systems using STRIDE, PASTA, Attack Trees, DREAD, LINDDUN, and OCTAVE. Use when assessing security architecture, creating data flow diagrams (Mermaid), enumerating threats from OpenAPI specs or architecture docs, building attack trees, mapping threats to NIST/CIS/OWASP ASVS controls, or producing a threat model report. Triggers on requests to threat model, analyze attack surface, create a DFD, apply STRIDE, or design security mitigations.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/threat-modeling

This session only. Nothing lands on disk.

methodologypasta.md

≈684 tokens on demand. Your agent reads this file only when SKILL.md points to it.

PASTA (Process for Attack Simulation and Threat Analysis)

A seven-stage, risk-centric methodology that aligns threat modeling with business objectives. Heavier than STRIDE; preferred for compliance-driven or business-critical assessments.

Stage 1: Define Business Objectives

  • Identify business objectives and success criteria
  • Capture security and compliance requirements (PCI DSS, HIPAA, GDPR, SOX)
  • Define risk tolerance / appetite
  • Inventory critical assets and their business value

Stage 2: Define Technical Scope

  • Document system architecture (logical + physical)
  • Technology stack and versions
  • Data flows (input: DFD from workflows/dfd_creation.md)
  • Integration points and third-party dependencies
  • Hosting and deployment topology

Stage 3: Application Decomposition

  • Identify components, services, and their owners
  • Map data flows between components
  • Identify assets (data + services) and classify
  • Define trust boundaries (see references/trust_boundary_patterns.md)
  • Build an Actor-Asset-Action matrix

Stage 4: Threat Analysis

  • Identify threat actors (script kiddie → nation state)
  • Enumerate threat scenarios using threat intelligence (MITRE ATT&CK, CTI feeds)
  • Map threats to attack patterns (CAPEC)
  • Consider motive, opportunity, capability

Stage 5: Vulnerability & Weakness Analysis

  • Enumerate known vulnerabilities (CVE, vendor advisories)
  • Identify design weaknesses (CWE)
  • Identify implementation flaws (SAST/DAST/SCA; see sast-orchestration and api-security skills)
  • Configuration issues (CIS benchmarks, cloud posture)

Stage 6: Attack Modeling & Simulation

  • Build attack trees per critical threat (see methodology/attack_trees.md)
  • Construct attack scenarios/kill chains
  • Analyze exploitability against each vulnerability
  • Estimate probability of attack success
  • Optionally simulate with red-team exercises

Stage 7: Risk & Impact Analysis

  • Calculate inherent and residual risk per scenario
  • Quantify impact (monetary, reputational, regulatory)
  • Prioritize by risk × impact
  • Plan mitigations, assign owners, track in risk register
  • Loop back to Stage 1 when business context changes

When to Choose PASTA

  • Regulated industries (finance, healthcare, critical infrastructure)
  • Enterprise-wide initiatives requiring business alignment
  • Cases where you need to justify security spend to leadership
  • When existing threat intelligence and CTI feeds should be integrated

When NOT to Choose PASTA

  • Small teams / single service — STRIDE is lighter
  • Rapid iteration / CI-integrated threat modeling — use STRIDE-per-interaction
  • Privacy-focused projects — use LINDDUN

See references/framework_comparison.md for a full decision matrix.

Source: SKILL.md on GitHub

No alerts16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The skill is safe. It consists entirely of markdown documentation, templates, and workflows for threat modeling methodologies (such as STRIDE, PASTA, and LINDDUN) to guide AI agent security reviews. It contains no executable code or scripts, and no malicious patterns were detected.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    1/1 file flagged

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/threat-modeling