threat

Installation
SKILL.md

Threat Modeling (Deep Workflow)

Threat modeling turns architecture into attack scenarios and mitigations before code hardens incorrectly. It is team-facing—security is a collaborative exercise, not a gate at the end.

When to Offer This Workflow

Trigger conditions:

  • New service, major data flow change, public API, partner integration
  • Compliance asks for “threat model” artifact
  • Post-incident “how do we prevent class of issues”

Initial offer:

Use six stages: (1) scope & assets, (2) diagram & trust boundaries, (3) threats (STRIDE), (4) mitigations & controls, (5) prioritize & owners, (6) validate & iterate. Confirm time box (1–2 hour workshop vs async).


Stage 1: Scope & Assets

Installs
4
First Seen
Apr 24, 2026
threat from skills.volces.com