ask-threats

Identify and analyze AI agent threats using the ASK threat model.

Updated Mar 15, 2026
One-click install
npx skills add https://github.com/geoffbelknap/geoffs-plugins --skill ask-threats
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: ask-threats
Source: https://github.com/geoffbelknap/geoffs-plugins/tree/main/plugins/ask-framework/skills/ask-threats
Command: npx skills add https://github.com/geoffbelknap/geoffs-plugins --skill ask-threats

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill provides a structured, framework-backed approach to identifying and analyzing threats to AI agent systems using the ASK threat model, enabling teams to map risks, assess kill chains, and design defenses.

Core Features & Use Cases

  • Threat categorization and risk assessment for traditional, novel, and hybrid threats to agents.
  • Kill-chain posture evaluation across injection, propagation, execution, and exfiltration stages with recommended mitigations.
  • Defensive architecture guidance for enforcing constraints, mediation, and gateway-level protections in MCP and delegation ecosystems.

Quick Start

Review your current agent threat model using the ASK framework and run an initial XPIA-focused risk inventory.

Frequently Asked Questions about ask-threats

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I analyze threats to AI agent systems using a structured framework?

Threat analysis for AI agent systems is performed using the ASK threat model to identify, categorize, and assess risks across traditional, novel, and hybrid threat classes. This approach maps risks and evaluates kill chains to guide defense-in-depth architecture design.

What is the best way to evaluate kill-chain posture for AI agents against XPIA and MCP tampering?

Evaluating kill-chain posture involves assessing injection, propagation, execution, and exfiltration stages to identify XPIA, MCP tampering, identity poisoning, and delegation risks. The analysis provides cross-stage risk assessment and recommended mitigations for each identified vulnerability.

How do I design defensive architecture for MCP and delegation ecosystems?

Defensive architecture design for MCP and delegation ecosystems enforces constraints, mediation, and gateway-level protections. This framework-backed approach ensures defense-in-depth guidance is applied to mitigate risks identified during agent threat modeling.

Can I use this threat analysis approach for both traditional and novel AI agent threats?

Yes, this threat analysis approach comprehensively catalogs both traditional and novel AI agent threats. It applies the ASK threat model to hybrid threat classes, satisfying cross-stage risk assessment and defense-in-depth guidance across the entire agent attack surface.

When do I need a structured threat model for AI agents instead of ad-hoc security reviews?

A structured threat model is needed when comprehensive threat cataloging and cross-stage risk assessment are required for AI agents. It maps kill chains and defense-in-depth guidance for XPIA and delegation risks that ad-hoc reviews typically miss.

Does analyzing agent threats with the ASK framework require any external dependencies?

No, analyzing agent threats with the ASK framework requires no external dependencies. It operates as a standalone security framework to identify attack surface risks and provide defensive architecture guidance without needing additional software libraries or components.