What problem does it solve?
This Skill helps you systematically uncover security threats in a system design, quantify risk using STRIDE, and translate findings into actionable security controls before implementation.
Core Features & Use Cases
- STRIDE threat identification: Organizes threats into Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege, mapped to violated security properties and mitigations.
- Risk scoring and prioritization: Uses a likelihood/impact matrix to compute risk levels and supports treatment decisions (e.g., immediate remediation for critical items).
- Reusable artifacts: Provides a STRIDE worksheet template, a reusable threat library, and example DFD/Threat Dragon model structures to speed consistent documentation.
- Use Case: Model the threat landscape for a new API gateway and trust boundaries, then produce a review-ready threat record with owners, gaps, and recommended mitigations.
Quick Start
Use the threat-modeling skill to produce a STRIDE worksheet for your API gateway, including threats, risk scores, existing controls, gaps, and recommended mitigations.