omh-application-threat-model

Installation
SKILL.md

Application Threat Model

This is a Hermes-native application-threat-model workflow skill.

Why This Exists

application-threat-model exists because the nearest neighbour does not merely miss this request. security-safety-review maps the agent's own prompt, tool, credential, and dependency surface, so an application threat-model request came back as an agent tool inventory under a near-identical name — a confident wrong artifact rather than a miss, in the one domain where that costs most.

Do Not Use When

  • The subject is the agent's own prompts, tools, files, credentials, dependencies, or destructive actions; use security-safety-review, which maps that runtime surface.
  • The user wants defects found in a diff or a file; use code-review.
  • The user asks whether a release is ready across rollout, rollback, and observability; use production-audit.
  • The user asks which commands prove a merge is safe; use verification-gate.
  • The user asks for a contractual or regulatory obligation rather than an attacker; use legal-compliance-review.

Examples

Good example:

Installs
7
GitHub Stars
3.0K
First Seen
11 days ago
omh-application-threat-model — rlaope/oh-my-hermes