What problem does it solve? Security teams often discover design-level vulnerabilities too late, after code review or penetration testing, when architectural flaws are expensive to fix. This Skill provides structured threat modeling methodologies to systematically identify what can go wrong before a system is built or shipped. ## Core Features & Use Cases - STRIDE Analysis: Apply the six STRIDE threat categories to data flow diagrams with trust boundaries, including a worked payment-service example and risk filtering by likelihood and impact. - Multiple Methodologies: Covers PASTA for risk-centric business-aligned analysis, LINDDUN for privacy threats, attack trees for modeling attacker goals, and MITRE ATT&CK for intelligence-driven technique mapping. - Agile Integration: Provides a lightweight 5-10 minute STRIDE workflow per user story with misuse story templates and acceptance criteria for sprint-level security. - Use Case: When designing a new payment API, use this Skill to draw trust boundaries, enumerate STRIDE threats per element, score risks with CVSS and EPSS, and produce a prioritized security backlog with business-impact framing. ## Quick Start Ask the AI to run a STRIDE threat model on your new system architecture, including trust boundaries, risk-rated threats, and mitigations.