skills/aibot88/sec_skill_store/performing-threat-modeling-with-owasp-threat-dragon/Gen Agent Trust Hub
performing-threat-modeling-with-owasp-threat-dragon
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues detected. The skill's primary function is to provide instructions and best practices for architectural security reviews using established methodologies like STRIDE and LINDDUN.
- [EXTERNAL_DOWNLOADS]: The skill references software downloads and Docker images from official and well-known sources, specifically the OWASP organization's GitHub repository and the official Docker Hub image. These are documented for legitimate installation purposes.
- [COMMAND_EXECUTION]: Provides a standard Docker command for self-hosting the Threat Dragon web application. The command includes security-conscious shell substitutions (
openssl rand) to ensure unique encryption keys are generated at runtime, which is a defensive best practice.
Audit Metadata