security-threat-model

Generate repo-specific threat models with trust boundaries, assets, and mitigations.

Updated Aug 23, 2026
One-click install
npx skills add https://github.com/ForeverWorld/curdx-ralph --skill security-threat-model-foreverworld
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-threat-model
Source: https://github.com/ForeverWorld/curdx-ralph/tree/main/skills/security-threat-model
Command: npx skills add https://github.com/ForeverWorld/curdx-ralph --skill security-threat-model-foreverworld

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Repo-grounded threat modeling tailored for AppSec engineers, anchoring architectural claims to evidence in the codebase and generating actionable risk insights.

Core Features & Use Cases

  • Evidence-backed system model: identify primary components, trust boundaries, assets, and entry points grounded in repository material.
  • Threat enumeration: produce attacker goals, abuse paths, and prioritized risks with concrete mitigations.
  • Automated guidance: yields a final threat-model artifact (text and diagram) ready for review and remediation planning.
  • Quick-start readiness: promotes rapid threat-modeling when repository context is available.

Quick Start

Provide a repo-scoped threat-model for the targeted codebase using repository evidence.

Frequently Asked Questions about security-threat-model

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate a threat model directly from my repository code?

Generate a repo-specific threat model by anchoring architectural claims to evidence in your codebase, identifying trust boundaries, assets, and entry points. It grounds every claim to a repo path or file to ensure evidence-backed risk insights.

What is repo-grounded threat modeling for AppSec?

Repo-grounded threat modeling for AppSec anchors architectural claims to repository evidence, producing actionable risk insights. It identifies trust boundaries, assets, attacker capabilities, abuse paths, and mitigations tailored to your specific codebase.

How do I identify trust boundaries and assets in my codebase for risk assessment?

Identify trust boundaries and assets by analyzing repository material to map primary components and entry points. The threat model grounds these architectural elements in specific repo paths, clearly stating assumptions if evidence is missing.

Can I produce a threat model diagram from my repository automatically?

Produce a threat model diagram automatically from your repository. The Skill yields a final threat-model artifact containing both text and a diagram, ready for AppSec review and remediation planning.

What is the best way to enumerate abuse paths and mitigations for application security?

Enumerate abuse paths and mitigations by generating attacker goals and prioritized risks with concrete mitigations. This approach delivers a compact, actionable report specifically designed for AppSec reviewers.

What happens if my repository lacks evidence for a complete threat model?

If your repository lacks evidence for a complete threat model, the process clearly states assumptions and open questions. It grounds every available architectural claim to a repo path while transparently highlighting missing evidence.