threat-model-generator
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [NO_CODE]: The skill does not provide any functional code or scripts for execution. It contains documentation, Markdown templates, and TypeScript interface definitions used to structure a threat modeling workflow.
- [DATA_EXPOSURE]: No hardcoded credentials or sensitive file paths were detected. References to 'passwords' or 'tokens' are illustrative examples within the asset identification and threat enumeration templates.
- [PROMPT_INJECTION]: The instructions focus entirely on the threat modeling methodology and do not contain any patterns typical of prompt injection or safety bypass attempts.
- [INDIRECT_PROMPT_INJECTION]: While the skill is intended to process user-provided system descriptions, it does not include any automated processing logic or tool invocations that would create a high-risk attack surface. The risk of the agent obeying malicious instructions embedded in analyzed documentation is mitigated by the lack of active capabilities in this skill.
Audit Metadata