security-threat-model

Generate repository-specific threat models with data flows, assets, and mitigations.

Updated Aug 23, 2026
One-click install
npx skills add https://github.com/allenbenj/pages --skill security-threat-model-allenbenj
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-threat-model
Source: https://github.com/allenbenj/pages/tree/main/.agents/skills/security-threat-model
Command: npx skills add https://github.com/allenbenj/pages --skill security-threat-model-allenbenj

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Threat modeling for repository-grounded security analyses, enabling concrete, evidence-backed risk assessments anchored to code and data flows.

Core Features & Use Cases

  • Repo-scoped threat modeling anchored to repository evidence, mapping assets, trust boundaries, and entry points.
  • Prioritized risk articulation with concrete attacker goals, abuse paths, and mitigations.
  • Structured workflow from system model to focused review and actionable recommendations.

Quick Start

Provide a repository or path context and invoke the threat-model workflow to generate an initial report.

Frequently Asked Questions about security-threat-model

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate a threat model from my repository code and data flows?

Generate a threat model by providing a repository or path context to anchor the analysis to code and data flows. The workflow maps assets, entry points, and trust boundaries to produce an evidence-backed risk assessment report with mitigations.

What is repo-tied AppSec threat modeling and when do I need it?

Repo-tied AppSec threat modeling is an evidence-backed risk assessment anchored to repository code and data flows. You need it to ground security analyses in concrete attacker goals, abuse paths, and prioritized mitigations rather than theoretical risks.

How do I map trust boundaries and entry points for an application security risk assessment?

Map trust boundaries and entry points by invoking the threat-model workflow on a repository context. It analyzes real-world usage and data flows to explicitly articulate attacker goals, abuse paths, and prioritized risk reasoning.

Can I use repository evidence to identify abuse paths and prioritize security mitigations?

Yes, you can use repository evidence to identify abuse paths and prioritize mitigations. The workflow generates a concise report including repo-relative focus paths, concrete attacker goals, and structured recommendations based on likelihood and impact reasoning.

What's the best way to scope an AppSec review to specific repo-relative focus paths?

Scope an AppSec review by running the threat-model workflow to generate repo-relative focus paths. The structured workflow progresses from system modeling to focused review, yielding actionable recommendations for targeted security analysis.

Does threat modeling work without external dependencies or specific platform setup?

Threat modeling works without external dependencies, requiring only a repository or path context to start. The workflow autonomously extracts evidence from the repo to map assets, data flows, and trust boundaries for an initial report.