What problem does it solve?
Most threat models in use as of mid-2026 are outdated, failing to account for modern AI-specific threats including AI agent actors, MCP supply chain risks, prompt injection as an access control bypass, and vector embedding data stores. Global security and AI frameworks also do not mandate current threat modeling methodologies, leading to compliance gaps, paper-only models, and unaddressed attack surfaces for AI and cloud-native systems.
Core Features & Use Cases
- Methodology Selection & Composition: Guides selection and combination of STRIDE, PASTA, LINDDUN, Diamond Model, MITRE Unified Kill Chain v3.0, and AI/agent-specific composite methodologies to match a system's unique threat surface, avoiding thin coverage from single-methodology use.
- Threat Mapping & Scoring: Enumerates threats per selected methodology, maps them to ATLAS, ATT&CK, CWE, and known CVEs, and scores relevant threats with RWEP (not CVSS alone) for accurate risk prioritization.
- Compliance & Operational Validation: Includes a compliance theater check to ensure models are co-located with the systems they cover, include AI actors, and meet cross-jurisdictional framework requirements, plus handoffs to downstream skills for currency assessment and mitigation mapping.
- Use Case: A team building an AI agent system with MCP plugins and RAG retrievers uses this skill to produce a threat model that covers agent trust boundaries, maps prompt injection risks to ATLAS TTPs, and meets EU AI Act, NIS2, and ISO 42001 requirements.
Quick Start
Use the threat-modeling-methodology skill to build a current, compliant threat model for your AI agent system that includes MCP server trust boundaries and maps all identified threats to relevant ATLAS and ATT&CK techniques.