security-threat-model

Installation
SKILL.md

Security Threat Model Skill

Overview

This skill executes a structured, phase-gated security threat model workflow that scans the toolkit installation for attack surface exposure, supply-chain injection patterns, and learning DB contamination. It follows the toolkit's four-layer architecture: deterministic Python scripts perform all checks and produce JSON artifacts; Phase 5 (synthesis only) is the LLM step. Each phase gates on artifact validation before proceeding.

Outputs are saved to security/ with a shared run_id for correlation across phases. Phase 5 produces an actionable threat model document.


Instructions

Phase 1: SURFACE SCAN

Related skills
Installs
4
GitHub Stars
366
First Seen
Mar 27, 2026