security-threat-model

Generate repo-specific threat models with evidence anchors from codebase paths.

Updated Aug 23, 2026
One-click install
npx skills add https://github.com/jbarlek3-web/claudecommandcenter --skill security-threat-model-jbarlek3-web
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-threat-model
Source: https://github.com/jbarlek3-web/claudecommandcenter/tree/main/skills/.curated/security-threat-model
Command: npx skills add https://github.com/jbarlek3-web/claudecommandcenter --skill security-threat-model-jbarlek3-web

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Repository-specific threat modeling that anchors architectural claims to code evidence, ensuring assumptions are explicit and threats are actionable for AppSec teams.

Core Features & Use Cases

  • Evidence-driven system modeling that binds every claim to a repo path.
  • Structured threat enumeration with prioritized abuse paths tailored to the codebase.
  • Reusable workflow and prompts aligned with the provided references.

Quick Start

Provide the repository path and scope, then ask the model to generate a repo-grounded threat model using the references/prompt-template guidelines.

Frequently Asked Questions about security-threat-model

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate an evidence-based threat model for my codebase?

Evidence-based threat modeling binds every architectural claim to a specific repository path. It focuses on actual assets, trust boundaries, entry points, and data flows rather than generic vulnerability checklists to produce actionable AppSec insights.

How do I map trust boundaries and data flows for application security analysis?

Map trust boundaries and data flows by analyzing your repository's entry points and attacker capabilities. This repo-grounded approach cites specific code paths to structure your application security analysis and prioritize threats accurately.

Can I use this threat modeling approach for any repository scope?

Yes, you can use this repo-grounded threat modeling approach for any repository scope. Provide the repository path and scope boundaries to generate a tailored threat model with explicit assumptions and prioritized abuse paths.

What do I need to start repo-grounded AppSec threat modeling?

To start repo-grounded AppSec threat modeling, provide the target repository path and define the analysis scope. The system then maps assets, trust boundaries, entry points, and data flows to generate a structured Markdown threat model.