threat-model-generator

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [NO_CODE]: The skill does not provide any functional code or scripts for execution. It contains documentation, Markdown templates, and TypeScript interface definitions used to structure a threat modeling workflow.
  • [DATA_EXPOSURE]: No hardcoded credentials or sensitive file paths were detected. References to 'passwords' or 'tokens' are illustrative examples within the asset identification and threat enumeration templates.
  • [PROMPT_INJECTION]: The instructions focus entirely on the threat modeling methodology and do not contain any patterns typical of prompt injection or safety bypass attempts.
  • [INDIRECT_PROMPT_INJECTION]: While the skill is intended to process user-provided system descriptions, it does not include any automated processing logic or tool invocations that would create a high-risk attack surface. The risk of the agent obeying malicious instructions embedded in analyzed documentation is mitigated by the lack of active capabilities in this skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 09:30 AM
Security Audit — agent-trust-hub — threat-model-generator