security-threat-model

Generate repository-grounded threat models with assets, trust boundaries, and abuse paths.

2|Updated Apr 11, 2026
One-click install
npx skills add https://github.com/JaimeJunr/context-mode --skill security-threat-model-jaimejunr
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-threat-model
Source: https://github.com/JaimeJunr/context-mode/tree/main/.claude/skills/security-threat-model
Command: npx skills add https://github.com/JaimeJunr/context-mode --skill security-threat-model-jaimejunr

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Threat modeling for a code repository anchored to concrete repo evidence, enabling security engineers to derive focused, evidence-based risk insights specific to the codebase.

Core Features & Use Cases

  • Anchors architectural claims to repository evidence (files, paths, symbols, and configurations).
  • Enumerates assets, trust boundaries, attacker capabilities, abuse paths, and mitigations tailored to the repository context.
  • Generates a prioritized threat model with explicit assumptions, evidence anchors, and remediation guidance for stakeholders.

Quick Start

Provide the repository root and scope to generate a tailored threat model for AppSec review.

Frequently Asked Questions about security-threat-model

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate a threat model for a specific code repository?

To generate a threat model, provide the repository root and scope. The analysis enumerates assets, trust boundaries, attacker capabilities, and concrete abuse paths for the codebase.

What is repository-grounded threat modeling for AppSec?

Repository-grounded threat modeling anchors architectural claims to concrete repo evidence like files, paths, and configurations. It enables security engineers to derive focused, evidence-based risk insights specific to the codebase.

How do you assess AppSec risk and identify trust boundaries in a codebase?

Assess AppSec risk by enumerating assets, trust boundaries, attacker goals, and concrete abuse paths. The threat model evaluates likelihood, impact, existing mitigations, and gaps for each identified threat.

Can I get evidence-anchored remediation guidance for identified security threats?

Yes, the threat model provides practical mitigations with targeted evidence anchors from the repository. It outputs explicit assumptions, evidence anchors, and remediation guidance for stakeholders.

Does this threat modeling approach work for any repository scope?

Yes, provide the repository root and scope to generate a tailored threat model for AppSec review. The analysis targets appsec risk specific to the repository and its critical paths.

Why does my threat model lack concrete evidence from the codebase?

Threat models lack concrete evidence when not anchored to repository files, paths, symbols, and configurations. This approach targets appsec risk by enumerating assets and abuse paths with targeted evidence anchors from the repo.