security-threat-model

Generate repository-scoped threat models with trust boundaries, assets, and mitigations.

302|22|Updated Feb 12, 2026
One-click install
npx skills add https://github.com/JetBrains/skills --skill security-threat-model-jetbrains
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-threat-model
Source: https://github.com/JetBrains/skills/tree/main/security-threat-model
Command: npx skills add https://github.com/JetBrains/skills --skill security-threat-model-jetbrains

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Repository-grounded threat modeling that anchors architectural claims to real evidence in the repository, delivering an actionable AppSec threat model tailored to a codebase. It helps teams focus on concrete risks and clear mitigations rather than generic checklists.

Core Features & Use Cases

  • Anchor architecture to repo evidence with explicit trust boundaries and assets.
  • Enumerate attacker goals, abuse paths, and prioritized mitigations.
  • Produce a ready-to-use threat-model document following a defined output contract.

Quick Start

Provide a repo URL and scope to generate a tailored threat model for that codebase.

Frequently Asked Questions about security-threat-model

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate a threat model anchored to evidence in my codebase?

To generate a repository-grounded threat model, provide a repo URL and scope to identify trust boundaries, assets, and abuse paths, producing a structured report with mitigations and risk ranking.

What is repo-grounded threat modeling and how does it differ from generic checklists?

Repo-grounded threat modeling anchors architectural claims to real evidence in the repository, delivering an actionable AppSec threat model tailored to your codebase rather than relying on generic security checklists.

Can I use this threat modeling approach for codebases of varying scope?

Yes, this threat modeling approach applies the model to codebases of varying scope to identify trust boundaries, assets, and abuse paths, generating a tailored threat-model report for the specified repository.

How do I identify trust boundaries and assets for application security risk analysis?

Identify trust boundaries and assets by generating a repository-scoped threat model that enumerates attacker goals and abuse paths, applying the model to your codebase to produce prioritized mitigations and evidence anchors.

Does the threat model report include risk ranking and mitigation strategies?

Yes, the threat model report includes risk ranking, prioritized mitigations, and evidence anchors, following a defined output contract to deliver an actionable AppSec threat model tailored to your codebase.

What's the best way to document abuse paths and attacker goals in my repository?

The best way to document abuse paths and attacker goals is to generate a structured threat-model report anchored to evidence in the codebase, enumerating attacker goals and prioritized mitigations for your application security analysis.