tm-report

Generate comprehensive risk reports from STRIDE-based threat modeling data.

8|1|Updated Jan 20, 2026
One-click install
npx skills add https://github.com/josemlopez/threat-modeling-toolkit --skill tm-report
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: tm-report
Source: https://github.com/josemlopez/threat-modeling-toolkit/tree/main/skills/tm-report
Command: npx skills add https://github.com/josemlopez/threat-modeling-toolkit --skill tm-report

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill consolidates risk findings and generates prioritized, executive-ready risk reports for threat modeling projects, reducing manual drafting time.

Core Features & Use Cases

  • Executive summaries: generate leadership-ready summaries from threat data.
  • Threat overview: compile threats, controls, and gaps into a single, navigable report.
  • Audit-ready documentation: structure reports to support compliance reviews and audits.

Quick Start

Run the command: /tm-report --format markdown --level executive --output risk-report.md

Frequently Asked Questions about tm-report

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate an executive risk report from STRIDE threat modeling data?

You can generate an executive risk report from STRIDE threat modeling data by running the /tm-report command, which aggregates threats, controls, and gaps into a structured markdown file for leadership review.

Can I create audit-ready compliance documentation directly from threat modeling findings?

Yes, you can create audit-ready compliance documentation directly from threat modeling findings. The skill structures aggregated threat data and control gaps into navigable reports suitable for compliance evidence and audits.

What is the best way to consolidate STRIDE assessment risks into a single summary?

The best way to consolidate STRIDE assessment risks into a single summary is to use a threat modeling report generator, which compiles threats, controls, and gaps into prioritized executive summaries.

Does the risk report output include both a leadership overview and detailed threat gaps?

Yes, the risk report output includes both a leadership overview and detailed threat gaps. It produces an executive summary alongside a comprehensive risk overview mapping identified threats to control gaps.

How do I format my threat model output as a markdown file for compliance reviews?

You can format your threat model output as a markdown file for compliance reviews by specifying the markdown format and output path in the report generation command, producing audit-ready documentation.