All skills
hardw00t avatar

/threat-modeling

@f9bb3b2

Systematic threat modeling skill for applications, APIs, and systems using STRIDE, PASTA, Attack Trees, DREAD, LINDDUN, and OCTAVE. Use when assessing security architecture, creating data flow diagrams (Mermaid), enumerating threats from OpenAPI specs or architecture docs, building attack trees, mapping threats to NIST/CIS/OWASP ASVS controls, or producing a threat model report. Triggers on requests to threat model, analyze attack surface, create a DFD, apply STRIDE, or design security mitigations.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/threat-modeling

This session only. Nothing lands on disk.

workflowsstride_from_openapi.md

≈1.1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Workflow: STRIDE-per-Interaction from OpenAPI/AsyncAPI

Key workflow. Frontier models can consume an OpenAPI/AsyncAPI document and auto-generate a STRIDE-per-interaction threat table. This short-circuits the slowest part of threat modeling.

Inputs

  • openapi.yaml / openapi.json (v3.x) OR asyncapi.yaml (v2/v3)
  • Optional: deployment / infra context (which services are internet-facing, what trust boundaries exist)
  • Optional: authn/authz scheme details beyond the spec

Outputs

  • STRIDE-per-interaction table (one row per operation)
  • Markdown threat catalog with schemas/finding.json-shaped findings
  • Prioritized mitigation list

Steps

1. Parse operations

For OpenAPI 3: iterate every {path}{method} pair. For each, record:

  • operationId, path, method
  • Request body schema & content types
  • Response bodies & status codes
  • Security requirements (security at global + operation level)
  • Parameters (path, query, header, cookie)
  • Tags (for grouping by trust zone)

For AsyncAPI: iterate every channel × operation pair. Record pub/sub direction, message schemas, bindings, security.

2. Classify each operation

Attach attributes to drive threat selection:

Attribute Values
Auth none / api_key / bearer / mTLS / OAuth2
Exposure internet / partner / internal
Side effects read / write / destructive / privileged
PII touched yes / no
Rate-limit-sensitive yes / no

3. Apply STRIDE per operation

For every operation, run this six-question checklist:

STRIDE Question Example Threat
S Can the caller identity be forged? Missing/weak auth, JWT alg=none, API key in URL
T Can request/response be modified undetected? No TLS, no HMAC, parameter tampering, mass assignment
R Can the caller deny having made the call? No audit log, shared service account, no request IDs
I Can the response leak data beyond what the caller should see? Verbose errors, BOLA/IDOR, sensitive fields in response, debug stacks
D Can the operation be used to exhaust resources? No rate limit, unbounded pagination/query, ReDoS-prone regex, large body
E Can this operation escalate privileges? Missing authz checks, broken function-level authz, role-editing endpoint open to normal users

4. Generate STRIDE-per-interaction table

Write one row per (operationId, STRIDE_category) where a threat exists. Use templates/stride_table.md for format.

5. Emit findings

Populate schemas/finding.json for each threat with:

  • threat_id like TM-{operationId}-{STRIDE-letter}-{n}
  • element.type = "data_flow" (or process for the backing service)
  • element.name = operationId
  • attack_vector filled from the threat description
  • mitigations mapped via workflows/threat_to_mitigation.md

6. Prioritize

Rank operations by: internet-exposed × destructive × PII × missing-control. Focus mitigation effort on top 20%.

Heuristics the Model Should Apply

  • Any security: [] at operation level on a non-idempotent endpoint: flag Spoofing + Elevation.
  • GET that accepts user-controlled ID in path and has a 200 response with object data: flag Information Disclosure (BOLA/IDOR) unless obvious tenant check exists.
  • POST / PUT / PATCH without response schema or returning full object: flag Mass Assignment / Info Disclosure.
  • Any endpoint with no rate-limit indicator and no auth: flag DoS.
  • Missing WWW-Authenticate 401 flow / vague 401s: flag Spoofing + Repudiation.
  • apiKey in query parameter (vs header): flag Info Disclosure (logs, referer leakage).
  • OAuth2 with implicit flow or password grant in new specs: flag Spoofing.
  • Server sends fields starting with _, internal, debug, password, hash, secret: flag Info Disclosure.

Parallelism

Process operations in batches across sub-agents. One sub-agent per tag group (or per STRIDE letter across all ops). See parent SKILL.md Sub-Agent Delegation.

Extended Thinking

Turn on extended thinking when:

  • The spec has >50 operations (strategic grouping matters)
  • Custom auth schemes need modeling
  • Cross-operation attack chains are possible (e.g., low-priv read + privileged write)

Complementary Skill

For runtime testing to confirm the identified threats are exploitable, hand off to the api-security skill.

Reference Template

See examples/stride_threat_library.md for pre-built threat patterns per element type.

Source: SKILL.md on GitHub

No alerts16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The skill is safe. It consists entirely of markdown documentation, templates, and workflows for threat modeling methodologies (such as STRIDE, PASTA, and LINDDUN) to guide AI agent security reviews. It contains no executable code or scripts, and no malicious patterns were detected.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    1/1 file flagged

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/threat-modeling