threat-model

Installation
SKILL.md

Security Threat Model

Objective

Establish the repository-scoped threat model at the path defined in ../../references/scan-artifacts.md. Reuse a cached model only when its final Repository and Version lines match the current target.

AGENTS.md or resolved SECURITY.md guidance can be that authoritative source when it is sufficiently specific about the repository's product surfaces, trust boundaries, attacker-controlled inputs, assumptions, or security scan guidance to serve as the threat model.

If no threat model is provided, generate a repository-scoped threat model to be used in future bug discovery. The threat model should holistically cover the entire repository and should make it obvious:

  • what assets or privileges matter
  • what trust boundaries exist
  • what inputs are attacker-controlled
  • what invariants the code must preserve
  • what repository-wide failure modes would matter most

Artifact Resolution

Installs
5
GitHub Stars
8.2K
First Seen
5 days ago
threat-model — openai/codex-security