omh-application-threat-model
Installation
SKILL.md
Application Threat Model
This is a Hermes-native application-threat-model workflow skill.
Why This Exists
application-threat-model exists because the nearest neighbour does not merely miss this request. security-safety-review maps the agent's own prompt, tool, credential, and dependency surface, so an application threat-model request came back as an agent tool inventory under a near-identical name — a confident wrong artifact rather than a miss, in the one domain where that costs most.
Do Not Use When
- The subject is the agent's own prompts, tools, files, credentials, dependencies, or destructive actions; use
security-safety-review, which maps that runtime surface. - The user wants defects found in a diff or a file; use
code-review. - The user asks whether a release is ready across rollout, rollback, and observability; use
production-audit. - The user asks which commands prove a merge is safe; use
verification-gate. - The user asks for a contractual or regulatory obligation rather than an attacker; use
legal-compliance-review.
Examples
Good example: