All skills
hardw00t avatar

/threat-modeling

@f9bb3b2

Systematic threat modeling skill for applications, APIs, and systems using STRIDE, PASTA, Attack Trees, DREAD, LINDDUN, and OCTAVE. Use when assessing security architecture, creating data flow diagrams (Mermaid), enumerating threats from OpenAPI specs or architecture docs, building attack trees, mapping threats to NIST/CIS/OWASP ASVS controls, or producing a threat model report. Triggers on requests to threat model, analyze attack surface, create a DFD, apply STRIDE, or design security mitigations.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/threat-modeling

This session only. Nothing lands on disk.

templatesstride_table.md

≈588 tokens on demand. Your agent reads this file only when SKILL.md points to it.

STRIDE Table Templates

STRIDE-per-Element Worksheet

One row per (element, STRIDE category) applicable combination. Use the element-type applicability matrix from methodology/stride.md.

Element Type S T R I D E
User external entity <threat/none> — <threat/none> — — —
Web API process <> <> <> <> <> <>
PostgreSQL data store — <> <> <> <> —
API → DB flow data flow — <> — <> <> —

Fill each cell with either a threat identifier (e.g. TM-001) or — for N/A.

STRIDE-per-Interaction Table (for API-heavy systems)

Generated from OpenAPI via workflows/stride_from_openapi.md.

Operation Method Path Auth Exposure S T R I D E
listUsers GET /users Bearer internet — — — TM-004 TM-005 TM-006
getUser GET /users/{id} Bearer internet — — — TM-007 (IDOR) — TM-008
createUser POST /users Bearer internet — TM-009 (mass assignment) — — — —
deleteUser DELETE /users/{id} Bearer + admin internet — — TM-010 (no audit) — — TM-011

Threat Detail Block (one per cell marked with an ID)

Threat ID: TM-007
Title: IDOR on GET /users/{id}
STRIDE: Information Disclosure
Element: data flow (API ↔ DB) + process (API server)
Attack Vector: Authenticated user substitutes another user's ID
  in the path and retrieves their record; server does not verify
  the requester's ownership / tenant.
Likelihood: High
Impact: High
Risk: 8 (PII exposure at scale)
Controls (Preventive): Ownership check in route handler;
  enforce row-level security at DB.
Controls (Detective): Alert on enumeration patterns
  (same user hitting /users/{id} with increasing IDs).
CWE: CWE-639
OWASP: API1:2023 (BOLA)
References: <OWASP API Sec Top 10>

Compact All-Threats Summary

For executive summary:

ID Title STRIDE Risk Status
TM-001 <short> <letters> <score> <proposed/planned/implemented/verified>

Sort by risk descending; highlight the top 20% separately.

Source: SKILL.md on GitHub

No alerts16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The skill is safe. It consists entirely of markdown documentation, templates, and workflows for threat modeling methodologies (such as STRIDE, PASTA, and LINDDUN) to guide AI agent security reviews. It contains no executable code or scripts, and no malicious patterns were detected.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    1/1 file flagged

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/threat-modeling