agentsclimarketplace

Threat modeler

Skill a5c-ai/babysitter/library/specializations/software-architecture/skills/threat-modeler

Generate threat models using STRIDE, PASTA, or VAST methodologiesFrom its SKILL.md

Install
npx -y skills add a5c-ai/babysitter --skill threat-modeler

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

SKILL.md

3.4 KB, 789 tokens by cl100k_base, as published. Nobody here has run it

Threat Modeler Skill

Overview

Generates threat models using STRIDE, PASTA, or VAST methodologies with attack tree generation, data flow diagram analysis, and threat prioritization using DREAD.

Capabilities

  • Generate STRIDE threat models
  • PASTA methodology support
  • VAST methodology support
  • Attack tree generation
  • Data flow diagram analysis
  • Threat prioritization (DREAD)
  • Microsoft Threat Modeling Tool integration
  • Mitigation recommendations

Target Processes

  • security-architecture-review
  • api-design-specification

Input Schema

{
  "type": "object",
  "required": ["system"],
  "properties": {
    "system": {
      "type": "object",
      "properties": {
        "name": { "type": "string" },
        "description": { "type": "string" },
        "dataFlows": { "type": "array" },
        "assets": { "type": "array" },
        "trustBoundaries": { "type": "array" },
        "externalEntities": { "type": "array" }
      }
    },
    "methodology": {
      "type": "string",
      "enum": ["STRIDE", "PASTA", "VAST"],
      "default": "STRIDE"
    },
    "options": {
      "type": "object",
      "properties": {
        "prioritization": {
          "type": "string",
          "enum": ["DREAD", "CVSS", "custom"],
          "default": "DREAD"
        },
        "generateAttackTrees": {
          "type": "boolean",
          "default": true
        },
        "outputFormat": {
          "type": "string",
          "enum": ["json", "markdown", "html"],
          "default": "markdown"
        }
      }
    }
  }
}

Output Schema

{
  "type": "object",
  "properties": {
    "threats": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": { "type": "string" },
          "category": { "type": "string" },
          "title": { "type": "string" },
          "description": { "type": "string" },
          "affectedAssets": { "type": "array" },
          "riskScore": { "type": "number" },
          "mitigations": { "type": "array" }
        }
      }
    },
    "attackTrees": {
      "type": "array"
    },
    "dataFlowDiagram": {
      "type": "string",
      "description": "DFD in specified format"
    },
    "summary": {
      "type": "object",
      "properties": {
        "totalThreats": { "type": "number" },
        "byCategory": { "type": "object" },
        "bySeverity": { "type": "object" }
      }
    }
  }
}

Usage Example

{
  kind: 'skill',
  skill: {
    name: 'threat-modeler',
    context: {
      system: {
        name: 'E-Commerce Platform',
        assets: ['User Data', 'Payment Info', 'Inventory'],
        trustBoundaries: ['DMZ', 'Internal Network'],
        dataFlows: [
          { from: 'User', to: 'Web Server', data: 'Credentials' }
        ]
      },
      methodology: 'STRIDE',
      options: {
        prioritization: 'DREAD',
        generateAttackTrees: true
      }
    }
  }
}

What ships with it: 1 file

392 B alongside SKILL.md

Keep looking

Skills are one crate of 326,059. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.