regulatory-threat-model
Regulatory Threat Model (STRIDE + LINDDUN)
Software gets built faster than it gets reviewed — especially software built by prompting an AI agent. This skill turns the same agent into the orchestrator of a real security review: a server-enforced STRIDE threat model, a LINDDUN privacy threat model when personal data flows, a dependency exposure screen against live vulnerability data, and a selected, non-exhaustive screen of EU security obligations — each obligation cited from served legal text with its scope, role, and application-date limits stated. The deliverable is a report the user can put in front of a customer, an auditor, or an investor — with its sources and unresolved items visible; not a chat transcript, and not a compliance verdict.
The threat-modeling workflows run on the Ansvar Gateway's workflow engine, which enforces steps and quality gates server-side. The agent's job is to feed the engine well and to ground the regulatory layer; it is never the engine.