threat-modeling

Installation
SKILL.md

Threat Modeling

Adversarial design-time analysis: enumerate threats against a system and specify mitigations. This skill routes to methodology files, workflow runbooks, example libraries, and control-catalog references. Extended adversarial reasoning is the core value — spend thinking budget on threat enumeration.

When to Use

  • New system or major architecture change needs security review.
  • An OpenAPI / AsyncAPI spec exists and you want automatic STRIDE-per-interaction.
  • Architecture docs or diagrams need threat analysis.
  • A specific high-impact threat requires attack-tree deep dive.
  • Privacy / personal-data handling needs threat analysis (LINDDUN).
  • Mitigations need mapping to NIST CSF / NIST 800-53 / CIS / OWASP ASVS.
  • Producing a threat model report for stakeholders / auditors.
  • Prioritizing existing threat lists by risk score.
Installs
23
GitHub Stars
95
First Seen
Feb 2, 2026
threat-modeling — hardw00t/ai-security-arsenal