regulatory-threat-model

Orchestrate cited STRIDE and LINDDUN threat modeling with live CVE and regulatory screening.

Updated Jul 21, 2026
One-click install
npx skills add https://github.com/Ansvar-Systems/regulatory-threat-model-skill --skill regulatory-threat-model
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: regulatory-threat-model
Source: https://github.com/Ansvar-Systems/regulatory-threat-model-skill/tree/main
Command: npx skills add https://github.com/Ansvar-Systems/regulatory-threat-model-skill --skill regulatory-threat-model

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps teams assess the security and privacy risks of an application without relying on improvised AI analysis or ungrounded legal conclusions. It coordinates a server-enforced threat-modeling workflow and produces cited research support that clearly separates confirmed findings, unresolved questions, and regulatory applicability limits.

Core Features & Use Cases

  • STRIDE threat modeling: Runs a server-enforced workflow that identifies per-component threats, affected assets, severity, mitigations, and relevant regulatory citations.
  • LINDDUN privacy analysis: Models privacy threats across personal-data flows, including potential harms and mitigations.
  • Dependency and regulatory screening: Checks named dependencies against live CVE, CISA KEV, and FIRST EPSS data, and evaluates selected GDPR, NIS2, Cyber Resilience Act, and AI Act obligations using citations from official sources.
  • Safe, transparent deliverables: Requires architecture-level user confirmation, avoids file and secret uploads, distinguishes retrieval failures from no-match results, and never presents the output as legal advice, a compliance verdict, a penetration test, or a code audit.
  • Use Case: A team launching an AI-enabled SaaS product can describe its architecture, data flows, dependencies, deployment context, and legal posture, then receive a cited security review with workflow reports, vulnerability exposure results, regulatory conditions, and unresolved determinations.

Quick Start

Ask the connected AI agent to threat-model your application and provide its architecture, data flows, key assets, named dependencies with versions, AI features, and coarse legal posture in prose.

Frequently Asked Questions about regulatory-threat-model

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I run a STRIDE threat model with EU regulatory citations?

You can run a STRIDE threat model by providing your application architecture, data flows, key assets, and dependencies to receive a server-enforced cited security review with per-component threats, mitigations, and relevant GDPR, NIS2, or AI Act conditions.

What is LINDDUN privacy threat modeling for application architectures?

LINDDUN privacy analysis models privacy threats across personal-data flows within your application architecture, identifying potential harms and matching them with appropriate mitigations to ensure data protection compliance.

Can I screen dependencies against live CVE and CISA KEV data?

Yes, you can screen named dependencies against live CVE, CISA KEV, and FIRST EPSS vulnerability data by providing the dependency names and versions in your architecture description to receive detailed exposure results.

Does this threat modeling workflow support Cyber Resilience Act and AI Act analysis?

Yes, the workflow supports conditional Cyber Resilience Act and AI Act analysis for software systems and AI-enabled services, evaluating specific regulatory obligations using citations retrieved from official legal sources.

Do I need the Ansvar Gateway MCP connector to run regulatory threat modeling?

Yes, the Ansvar Gateway MCP connector is required for regulatory threat modeling because it enforces server-side workflows, official legal text retrieval, vulnerability data checks, consent gates, and report generation.

What are the limitations of using AI for security and privacy reviews?

Limitations include that the output is never presented as legal advice, a compliance verdict, a penetration test, or a code audit, and the workflow requires architecture-level user confirmation while avoiding file and secret uploads.