security-threat-model

Generate a repo-grounded threat model with assets, trust boundaries, and mitigations.

Updated Mar 29, 2026
One-click install
npx skills add https://github.com/oiagorodrigues/qcontabil --skill security-threat-model-oiagorodrigues
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-threat-model
Source: https://github.com/oiagorodrigues/qcontabil/tree/main/.cursor/skills/security-threat-model
Command: npx skills add https://github.com/oiagorodrigues/qcontabil --skill security-threat-model-oiagorodrigues

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Threat modeling in code repositories is often ad hoc; this skill provides repo-grounded threat modeling anchored to concrete evidence from the repository to support precise risk assessment and prioritized mitigations.

Core Features & Use Cases

  • Anchors architectural claims to repository evidence from code, commits, and references.
  • Enumerates assets, trust boundaries, attacker capabilities, abuse paths, and mitigations for reproducible reviews.
  • Delivers an actionable threat model tailored to the repository suitable for AppSec teams.

Quick Start

Generate a repo-grounded threat model from this repository's contents and references.

Frequently Asked Questions about security-threat-model

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I create a threat model from my repository code?

Repo-grounded threat modeling anchors architectural claims to concrete evidence from your codebase, commits, and references. It scopes the model to the repository's real usage, identifying assets, trust boundaries, entry points, and mitigations for reproducible risk assessment.

What is repo-grounded threat modeling for AppSec risk analysis?

Repo-grounded threat modeling is a risk analysis technique that maps assets, trust boundaries, and attacker capabilities directly to evidence in your codebase. It replaces ad hoc AppSec reviews with reproducible, evidence-backed threat prioritization.

How do I identify trust boundaries and entry points in my codebase?

Threat modeling scopes your repository's real usage to enumerate trust boundaries, entry points, and attacker capabilities. It anchors these architectural claims to concrete evidence from the code, commits, and references for precise risk assessment.

Can I prioritize security threats based on likelihood and impact for my repository?

Repo-grounded threat modeling delivers prioritized threats with likelihood, impact, assets impacted, existing controls, gaps, and concrete mitigations. This AppSec prioritization is tailored to your repository and suitable for follow-up security review.

Does threat modeling work for analyzing existing security controls and gaps?

Threat modeling evaluates your repository's real usage to identify existing controls and security gaps. It delivers an actionable threat model highlighting missing mitigations anchored to concrete evidence from the codebase and references.

What's the best way to generate an actionable threat model for AppSec teams?

Repo-grounded threat modeling produces an actionable threat model tailored to your repository for AppSec teams. It anchors architectural claims to codebase evidence, enumerating abuse paths and mitigations suitable for follow-up review.