What problem does it solve?
This Skill helps security engineers produce focused, evidence-anchored threat models for a repository or a specific project path so reviewers get actionable abuse paths and prioritized mitigations rather than generic checklists.
Core Features & Use Cases
- Repository-grounded analysis: enumerates trust boundaries, assets, entry points, attacker capabilities, and concrete abuse paths tied to repo evidence.
- Prioritization & mitigation: provides qualitative likelihood/impact reasoning and concrete, location-specific mitigations and detection ideas.
- Interactive validation: surfaces key assumptions and asks targeted questions before finalizing the report to avoid mis-scoping.
- Use Case: security reviewer asks for a threat model of a codebase or subpath and receives a concise Markdown report with evidence anchors and a mermaid diagram.
Quick Start
Use the security-threat-model skill to produce an evidence-anchored threat model for the repository or a specified subpath, asking the user to confirm deployment and exposure assumptions first.