All skills
hardw00t avatar

/threat-modeling

@f9bb3b2

Systematic threat modeling skill for applications, APIs, and systems using STRIDE, PASTA, Attack Trees, DREAD, LINDDUN, and OCTAVE. Use when assessing security architecture, creating data flow diagrams (Mermaid), enumerating threats from OpenAPI specs or architecture docs, building attack trees, mapping threats to NIST/CIS/OWASP ASVS controls, or producing a threat model report. Triggers on requests to threat model, analyze attack surface, create a DFD, apply STRIDE, or design security mitigations.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/threat-modeling

This session only. Nothing lands on disk.

templatesthreat_model_report.md

≈949 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Threat Model Report Template

Copy and fill. Keep per-threat entries aligned to schemas/finding.json.


Threat Model: <System Name>

Document Information

  • Application / System: <name>
  • Version: <x.y.z>
  • Date: YYYY-MM-DD
  • Author(s): <names>
  • Reviewers: <names>
  • Methodology: STRIDE / PASTA / LINDDUN / Attack Trees / ...
  • Last Validated: YYYY-MM

Executive Summary

One-paragraph summary: what the system is, the most critical threats identified, overall residual risk posture, and top recommendations.

Scope & Assumptions

  • In scope: components, interfaces, data types
  • Out of scope: what is excluded and why
  • Assumptions: e.g. "TLS 1.3 is used everywhere", "attacker is not a nation-state", "cloud provider control plane is trusted"

System Overview

Architecture

Render the DFD (Mermaid). Level-0 for overview; Level-1+ for detail. See workflows/dfd_creation.md.

flowchart LR
    %% Level-0 context diagram here

Components

Component Description Technology Owner
<name> <role> <stack> <team>

Actors

Actor Description Trust Level
End user <...> Untrusted
Admin <...> Privileged
Service <x> <...> Trusted

Assets

Asset Classification Integrity Availability Regulatory
User credentials Confidential Critical Critical -
PII (email, name) Confidential High High GDPR
Session tokens Confidential High High -

Trust Boundaries

Reference references/trust_boundary_patterns.md.

  1. Internet ↔ DMZ
  2. DMZ ↔ Application tier
  3. Application ↔ Data tier
  4. Tenant ↔ Tenant (multi-tenant isolation)
  5. Admin ↔ User (privilege)

Threat Analysis

Threat: TM-001 — <short title>

  • STRIDE Category: <S/T/R/I/D/E> (may be multiple)
  • Element: <name> (<process / data store / data flow / external entity>)
  • Trust Boundary: <boundary name>
  • Attack Vector: <how an attacker realizes this>
  • Attacker Profile: <unauthenticated_internet / authenticated_user / privileged / insider / supply_chain / physical>
  • Likelihood: High / Medium / Low
  • Impact: Critical / High / Medium / Low
  • Risk Score: <0-10>
  • DREAD (if used): D=<> R=<> E=<> A=<> D=<> → <avg>
  • CWE / CAPEC / ATT&CK: <CWE-89 / CAPEC-66 / T1190>

Current State: <existing controls and gaps>

Proposed Mitigations:

  • Preventive: <control>
  • Detective: <control>
  • Corrective: <control>

Control Mappings:

  • NIST 800-53: <IA-2, SC-8, ...>
  • OWASP ASVS: <V2.2.1, ...>
  • CIS: <6.5, ...>

Residual Risk: <Low after mitigation>


Repeat per threat.

Attack Trees (for high-impact threats)

Embed key attack trees per workflows/attack_tree_from_threat.md.

Risk Summary

ID Threat STRIDE Risk Status Mitigation Residual
TM-001 <title> S+E 8.4 Planned Parameterized queries Low
TM-002 <title> I 7.2 Implemented Output encoding Low

Recommendations

Priority 1 (Immediate — this sprint)

  1. <action>
  2. <action>

Priority 2 (Short-term — this quarter)

  1. <action>

Priority 3 (Long-term — roadmap)

  1. <action>

Assumptions and Open Questions

  • <unresolved question> — requires input from <team>

Appendix

  • Full DFD (Level-0 and Level-1)
  • STRIDE-per-element worksheet
  • Control implementation details
  • References: links to architecture docs, OpenAPI specs, prior threat models

Source: SKILL.md on GitHub

No alerts16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The skill is safe. It consists entirely of markdown documentation, templates, and workflows for threat modeling methodologies (such as STRIDE, PASTA, and LINDDUN) to guide AI agent security reviews. It contains no executable code or scripts, and no malicious patterns were detected.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    1/1 file flagged

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/threat-modeling