All skills
wshobson avatar

/stride-analysis-patterns

@be57c0b
by Seth Hobsonwshobson/agents40k stars
4,281

Apply STRIDE methodology to systematically identify threats. Use when analyzing system security, conducting threat modeling sessions, or creating security documentation.

Use this Skill: https://skilld.dev/gh/wshobson/agents/stride-analysis-patterns

This session only. Nothing lands on disk.

SKILL.md

≈49 tokens always: the name and description. ≈557 when used: this file. ≈4.6k more on demand in 1 file.

STRIDE Analysis Patterns

Systematic threat identification using the STRIDE methodology.

When to Use This Skill

  • Starting new threat modeling sessions
  • Analyzing existing system architecture
  • Reviewing security design decisions
  • Creating threat documentation
  • Training teams on threat identification
  • Compliance and audit preparation

Core Concepts

1. STRIDE Categories

S - Spoofing       → Authentication threats
T - Tampering      → Integrity threats
R - Repudiation    → Non-repudiation threats
I - Information    → Confidentiality threats
    Disclosure
D - Denial of      → Availability threats
    Service
E - Elevation of   → Authorization threats
    Privilege

2. Threat Analysis Matrix

Category Question Control Family
Spoofing Can attacker pretend to be someone else? Authentication
Tampering Can attacker modify data in transit/rest? Integrity
Repudiation Can attacker deny actions? Logging/Audit
Info Disclosure Can attacker access unauthorized data? Encryption
DoS Can attacker disrupt availability? Rate limiting
Elevation Can attacker gain higher privileges? Authorization

Templates and detailed worked examples

Full template library lives in references/details.md. Read that file when you need concrete templates for this skill.

Best Practices

Do's

  • Involve stakeholders - Security, dev, and ops perspectives
  • Be systematic - Cover all STRIDE categories
  • Prioritize realistically - Focus on high-impact threats
  • Update regularly - Threat models are living documents
  • Use visual aids - DFDs help communication

Don'ts

  • Don't skip categories - Each reveals different threats
  • Don't assume security - Question every component
  • Don't work in isolation - Collaborative modeling is better
  • Don't ignore low-probability - High-impact threats matter
  • Don't stop at identification - Follow through with mitigations

Source: SKILL.md on GitHub

No alerts16d5 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    This skill provides a systematic framework for identifying security threats using the STRIDE methodology. It includes informational markdown templates and logical Python class definitions for modeling threats and data flows. The skill is purely educational and architectural, containing no malicious code, remote dependencies, or security bypass attempts.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer6mo

    1 file scanned · No issues

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at be57c0b. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated 4 months ago
  • Security
  • stride
  • threat-modeling
  • authentication
  • integrity
  • confidentiality
  • authorization
  • compliance

README badge

README badge for wshobson/agents/stride-analysis-patterns

Applies the STRIDE threat modeling framework to systematically identify authentication, integrity, confidentiality, availability, and authorization threats across system components. Use this skill when conducting threat modeling sessions, reviewing architecture security, or creating threat documentation.

Generated from the current SKILL.md.

What is STRIDE and how does this skill apply it?
STRIDE is a threat modeling framework that categorizes security threats into six types: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege. This skill provides a systematic methodology and templates to identify threats in each category during threat modeling sessions.
Can I use this skill for compliance and audit preparation?
Yes. The skill is designed for compliance and audit preparation, as well as creating threat documentation and training teams on threat identification.
Does this skill provide actual threat templates?
Yes. The skill includes a template library in `references/details.md` with concrete templates and worked examples for threat analysis.
Do I need a specific tool or format to use this skill?
The skill works with threat modeling conversations and system architecture review. It references DFDs (Data Flow Diagrams) as visual aids but does not require a specific diagramming tool.

Generated from the current SKILL.md. These answers refresh after source changes.