threat-modeler

Perform STRIDE threat modeling and privacy impact assessments to generate security requirement artifacts.

50|9|Updated Feb 5, 2026
One-click install
npx skills add https://github.com/Agile-V/agile_v_skills --skill threat-modeler-agile-v
Or copy as Structured Prompt for Agentā–¼
Please help me install this Agent Skill.
Skill: threat-modeler
Source: https://github.com/Agile-V/agile_v_skills/tree/main/threat-modeler
Command: npx skills add https://github.com/Agile-V/agile_v_skills --skill threat-modeler-agile-v

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

STRIDE threat modeling and privacy impact assessment are applied early in requirements to transform security into actionable requirements, ensuring critical issues are identified before design.

Core Features & Use Cases

  • STRIDE-based decomposition: map entities, data flows, trust boundaries, and data stores to document threats.
  • Privacy assessment: inventory PII, map data flows, assess risks, and capture mitigation concepts.
  • Output and handoff: generate THREAT_MODEL.md, PRIVACY_IMPACT_ASSESSMENT.md and hand off to requirement-architect for formalization.

Quick Start

Begin threat-modeling in the requirements phase to generate CRITICAL security/privacy candidate REQs and hand them to the requirement-architect.

Frequently Asked Questions about threat-modeler

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform STRIDE threat modeling during the requirements phase?ā–¼

A privacy impact assessment inventories PII, maps data flows, assesses risks, and captures mitigation concepts early in requirements to generate CRITICAL privacy candidate requirements before design begins.

What is the best way to shift security left with threat modeling?ā–¼

This approach generates formal artifacts like THREAT_MODEL.md and PRIVACY_IMPACT_ASSESSMENT.md, providing a structured handoff to requirement-architect for formalization.

How do I identify trust boundaries and data flows for secure design?ā–¼

This decomposition process ensures critical security and privacy candidate requirements are captured and prioritized during the requirements phase.

Does threat modeling work for privacy impact assessments and PII mapping?ā–¼

This ensures privacy risks are transformed into actionable candidate requirements alongside security threats.

When do I need to generate threat model artifacts for requirement handoff?ā–¼

This structured handoff ensures security and privacy issues are integrated into formal requirements before design begins.