security-threat-modeler

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides structured guidance and comprehensive reference templates for identifying architectural vulnerabilities based on established security frameworks (STRIDE and DREAD). The provided documentation (attack trees and methodology guides) is strictly educational and supports the stated purpose.\n- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted system architecture descriptions and data flow diagrams. While this represents a data ingestion surface, the agent's specific persona as a Senior Security Architect tasked with critical analysis acts as a robust behavioral boundary against following instructions that might be embedded in the design documents under review.\n
  • Ingestion points: Architectural descriptions and Data Flow Diagrams defined as inputs in SKILL.md.\n
  • Boundary markers: The instructions mandate the use of the STRIDE model for all analysis, providing a structured processing framework for inputs.\n
  • Capability inventory: Metadata indicates file creation capabilities for generating threat model reports.\n
  • Sanitization: Not applicable, as the agent is expected to interpret and report on the provided data qualitatively.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 06:53 PM
Security Audit — agent-trust-hub — security-threat-modeler