All skills
wshobson avatar

/attack-tree-construction

@be57c0b
by Seth Hobsonwshobson/agents40k stars
4,281

Build comprehensive attack trees to visualize threat paths. Use when mapping attack scenarios, identifying defense gaps, or communicating security risks to stakeholders.

Use this Skill: https://skilld.dev/gh/wshobson/agents/attack-tree-construction

This session only. Nothing lands on disk.

SKILL.md

β‰ˆ49 tokens always: the name and description. β‰ˆ598 when used: this file. β‰ˆ5k more on demand in 1 file.

Attack Tree Construction

Systematic attack path visualization and analysis.

When to Use This Skill

  • Visualizing complex attack scenarios
  • Identifying defense gaps and priorities
  • Communicating risks to stakeholders
  • Planning defensive investments
  • Penetration test planning
  • Security architecture review

Core Concepts

1. Attack Tree Structure

                    [Root Goal]
                         |
            β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
            β”‚                         β”‚
       [Sub-goal 1]              [Sub-goal 2]
       (OR node)                 (AND node)
            β”‚                         β”‚
      β”Œβ”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”             β”Œβ”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”
      β”‚           β”‚             β”‚           β”‚
   [Attack]   [Attack]      [Attack]   [Attack]
    (leaf)     (leaf)        (leaf)     (leaf)

2. Node Types

Type Symbol Description
OR Oval Any child achieves goal
AND Rectangle All children required
Leaf Box Atomic attack step

3. Attack Attributes

Attribute Description Values
Cost Resources needed $, $$, $$$
Time Duration to execute Hours, Days, Weeks
Skill Expertise required Low, Medium, High
Detection Likelihood of detection Low, Medium, High

Templates and detailed worked examples

Full template library lives in references/details.md. Read that file when you need concrete templates for this skill.

Best Practices

Do's

  • Start with clear goals - Define what attacker wants
  • Be exhaustive - Consider all attack vectors
  • Attribute attacks - Cost, skill, and detection
  • Update regularly - New threats emerge
  • Validate with experts - Red team review

Don'ts

  • Don't oversimplify - Real attacks are complex
  • Don't ignore dependencies - AND nodes matter
  • Don't forget insider threats - Not all attackers are external
  • Don't skip mitigations - Trees are for defense planning
  • Don't make it static - Threat landscape evolves

Source: SKILL.md on GitHub

1 warning16d5 checks Β· Risk SAFE
  • Gen Agent Trust Hub16d

    The skill provides templates and best practices for creating attack trees to visualize security threats. It includes Python templates for data modeling and analysis, which are safe for use as they do not perform network operations, file access, or command execution.

  • Socket16d

    1 alert: gptAnomaly

  • Snyk16d

    Risk: LOW Β· No issues

  • Runlayer6mo

    1 file scanned Β· No issues

  • ZeroLeaks5mo

    Score: 93/100 Β· 2 sections analyzed

Signed by skilld at be57c0b. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 3 days ago.

Activeupdated 4 months ago
  • Security
  • attack-tree
  • threat-modeling
  • penetration-testing
  • risk-assessment
  • defense-planning
  • architecture-review

README badge

README badge for wshobson/agents/attack-tree-construction

Constructs attack trees to map threat paths, visualize attack scenarios, and identify defense gaps using OR/AND node logic and cost/skill/detection attributes. Use for penetration test planning, security architecture review, or communicating risks to stakeholders.

Generated from the current SKILL.md.

What format does this skill use to represent attack trees?
The skill uses OR nodes (oval), AND nodes (rectangle), and leaf nodes (box) to structure attack paths. OR nodes mean any child achieves the goal; AND nodes require all children to succeed.
What attributes can I assign to attacks in the tree?
You can assign cost (resource level), time (duration to execute), skill (expertise required), and detection (likelihood of being caught) to each attack step.
Does this skill include templates?
Yes. The skill references a template library in `references/details.md` that contains concrete templates and worked examples for attack tree construction.
Is this skill meant for offense or defense?
This is a defensive tool. It's designed for identifying defense gaps, planning defensive investments, security architecture review, and communicating risks to stakeholders.

Generated from the current SKILL.md. These answers refresh after source changes.