threat-model-currency

Score organizational threat models against a 14-class mid-2026 threat checklist.

Updated May 11, 2026
One-click install
npx skills add https://github.com/blamejs/exceptd-skills --skill threat-model-currency
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: threat-model-currency
Source: https://github.com/blamejs/exceptd-skills/tree/main/skills/threat-model-currency
Command: npx skills add https://github.com/blamejs/exceptd-skills --skill threat-model-currency

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Most organizational threat models are 2–4 years outdated, built for 2021–2022 threat landscapes and missing critical 2026 attack patterns including AI-discovered kernel vulnerabilities, prompt injection RCE, MCP supply chain attacks, and AI-powered phishing. This leaves teams with a false sense of security against current, active threats that existing controls cannot mitigate.

Core Features & Use Cases

  • 14-Class 2026 Threat Checklist: Covers all mid-2026 threat classes from AI-discovered LPEs to post-quantum adversary timelines, with explicit currency check questions for each class.
  • Scored Currency Rating: Computes a 0–28 point score with clear tiered ratings (Current to Critically stale) to quantify exactly how outdated a threat model is.
  • Prioritized Update Roadmap: Generates actionable, gap-specific updates mapped to MITRE ATLAS/ATT&CK TTPs and D3FEND defensive controls, ordered by current exposure risk.
  • Compliance Theater Checks: Includes validated tests to distinguish operational threat models from outdated compliance artifacts, with coverage for global frameworks including NIST, ISO, EU NIS2/DORA, and UK NCSC CAF.
  • Use Case: A security governance team can use this skill to audit their existing threat model, identify gaps like missing MCP supply chain coverage or unaddressed AI-speed reconnaissance thresholds, and produce a defensible update plan for leadership and auditors.

Quick Start

Use the threat-model-currency skill to score your organization's current threat model against the 14 mid-2026 threat classes and generate a prioritized update roadmap.

Frequently Asked Questions about threat-model-currency

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I audit my threat model against 2026 cyber threat landscapes?

Threat model currency assessment identifies outdated coverage gaps by scoring your existing model against a 14-class mid-2026 threat checklist. It computes a 0-28 point rating to quantify staleness against emerging TTPs like prompt injection RCE, AI-discovered kernel vulnerabilities, and MCP supply chain attacks.

What emerging attack patterns should a threat model cover for 2026?

A 2026 threat model should cover AI-discovered kernel vulnerabilities, prompt injection RCE, MCP supply chain attacks, AI-powered phishing, and post-quantum adversary timelines. Threat model currency assessment validates your coverage against these 14 specific mid-2026 threat classes.

How do I check if my compliance threat model is outdated?

Compliance theater checks identify outdated threat models by validating operational coverage against global frameworks including NIST, ISO, EU NIS2/DORA, and UK NCSC CAF. This distinguishes active security artifacts from stale compliance documents missing modern attack pattern defenses.

Can I generate a threat model update roadmap mapped to MITRE ATLAS?

Yes, a prioritized update roadmap maps gap-specific updates to MITRE ATLAS and ATT&CK TTPs alongside D3FEND defensive controls. The roadmap orders threat model updates by current exposure risk to address missing coverage for AI threats and modern application stacks.

Does threat model currency assessment work for AI systems and Linux kernel infrastructure?

Threat model currency assessment works for environments with AI systems, Linux kernel infrastructure, and modern application stacks. It evaluates security gap analysis needs by checking for unaddressed AI-speed reconnaissance thresholds and missing MCP supply chain coverage specific to these platforms.

What is the best way to quantify threat model freshness for auditors?

Computing a standardized 0-28 point currency score with tiered ratings from Current to Critically stale provides a defensible, auditable metric to measure threat model freshness for auditors. This quantifies exactly how outdated threat models are against emerging TTPs for leadership review.