threat-model-generation
Pass
Audited by Gen Agent Trust Hub on Jul 9, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a standard security auditing workflow using the STRIDE methodology. It operates entirely on local files within the user's repository.
- [SAFE]: References to external documentation target reputable documentation and well-known security resources to provide context for threat modeling.
- [COMMAND_EXECUTION]: The skill includes a verification section that uses standard shell utilities (test, grep, jq) to ensure the generated security documentation is correctly formatted and present. These operations are limited to the project's local environment.
- [DATA_EXFILTRATION]: While the skill instructs the agent to identify sensitive assets such as PII and credentials as part of the threat modeling process, it does not include any instructions or tools for transmitting this data externally.
Audit Metadata