What problem does it solve?
Most organizational threat models are 2–4 years outdated, built for 2021–2022 threat landscapes and missing critical 2026 attack patterns including AI-discovered kernel vulnerabilities, prompt injection RCE, MCP supply chain attacks, and AI-powered phishing. This leaves teams with a false sense of security against current, active threats that existing controls cannot mitigate.
Core Features & Use Cases
- 14-Class 2026 Threat Checklist: Covers all mid-2026 threat classes from AI-discovered LPEs to post-quantum adversary timelines, with explicit currency check questions for each class.
- Scored Currency Rating: Computes a 0–28 point score with clear tiered ratings (Current to Critically stale) to quantify exactly how outdated a threat model is.
- Prioritized Update Roadmap: Generates actionable, gap-specific updates mapped to MITRE ATLAS/ATT&CK TTPs and D3FEND defensive controls, ordered by current exposure risk.
- Compliance Theater Checks: Includes validated tests to distinguish operational threat models from outdated compliance artifacts, with coverage for global frameworks including NIST, ISO, EU NIS2/DORA, and UK NCSC CAF.
- Use Case: A security governance team can use this skill to audit their existing threat model, identify gaps like missing MCP supply chain coverage or unaddressed AI-speed reconnaissance thresholds, and produce a defensible update plan for leadership and auditors.
Quick Start
Use the threat-model-currency skill to score your organization's current threat model against the 14 mid-2026 threat classes and generate a prioritized update roadmap.