Threat modeling
Skill kimtth/agent-skill-100-lines-or-less/skills/threat-modeling
🧿 Minimal but effective AI agent skill definitions in 100 lines or less.
npx -y skills add kimtth/agent-skill-100-lines-or-less --skill threat-modelingAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
2 things to look at
- no licenseNo license file was found in the repository. Code published without one is not open source by default, so using it at work is a question for whoever answers licensing questions where you are.
- 2 stars2 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Use when: systematically identify threats to a system and decide how to mitigate them.
SKILL.md
1.0 KB, as published. Nobody here has run it
Goal: understand what can go wrong before it does, and plan mitigations.
Use for:
- designing a new feature or system with security in mind
- finding attack surfaces and abuse cases
- prioritizing security work by risk
Workflow:
- Diagram the system: components, data flows, and trust boundaries.
- Identify assets worth protecting and who might attack them.
- Enumerate threats per element (e.g. with STRIDE).
- Rate each by likelihood and impact.
- Decide to mitigate, accept, transfer, or eliminate.
- Track mitigations as concrete, testable work.
STRIDE prompts:
- Spoofing, Tampering, Repudiation
- Information disclosure, Denial of service
- Elevation of privilege
Rules:
- model around data flows and trust boundaries
- focus effort on high-likelihood, high-impact threats
- record accepted risks explicitly, with rationale
- turn mitigations into verifiable tasks, not intentions