threat-model
minagayid/Agents/skills/library/threat-model/SKILL.md
Produce a threat model for a system or feature using STRIDE and data-flow analysis. Use when the user asks to threat-model, assess attack surface, or plan security for a design.
Skill1 starsChanged 3 months ago
What's in it
- Threat Model
- Steps
- Deliverable
- Guidelines
---
name: threat-model
description: Produce a threat model for a system or feature using STRIDE and data-flow analysis. Use when the user asks to threat-model, assess attack surface, or plan security for a design.
---
# Threat Model
Systematically enumerate how a system could be attacked and what to do about it.
## Steps
1. **Scope & assets.** What are we protecting (data, funds, availability, trust)? Who are the actors?
2. **Draw the data flow.** External entities, processes, data stores, and the flows between them.
Mark **trust boundaries** (where data crosses privilege levels).
3. **Enumerate threats with STRIDE** per element/flow:
- **S**poofing · **T**ampering · **R**epudiation · **I**nformation disclosure ·
**D**enial of service · **E**levation of privilege
4. **Rate** each threat by likelihood × impact; focus on what crosses trust boundaries.
5. **Mitigate.** For each significant threat, name a control (authN, input validation, encryption,
rate limiting, least privilege, logging) and who owns it.
6. **Track residual risk** you're accepting and why.
## Deliverable
A table: element/flow · STRIDE category · threat · likelihood/impact · mitigation · status.
Plus a short list of the top risks and recommended next actions.
## Guidelines
- Concentrate on trust boundaries — that's where most real vulnerabilities live.
- Prefer eliminating a threat (design change) over detecting it.
- Keep it living: revisit when the design or data flows change.
More agent context in minagayid/Agents
25 other files this repository gives its agents.
Skill
- agent-project-scaffoldskills/agent-project-scaffold/SKILL.md
- accessibility-auditskills/library/accessibility-audit/SKILL.md
- changelog-keeperskills/library/changelog-keeper/SKILL.md
- code-review-checklistskills/library/code-review-checklist/SKILL.md
- conventional-commitsskills/library/conventional-commits/SKILL.md
- data-cleaningskills/library/data-cleaning/SKILL.md
- debugging-methodologyskills/library/debugging-methodology/SKILL.md
- dependency-auditskills/library/dependency-audit/SKILL.md
- dockerfile-authorskills/library/dockerfile-author/SKILL.md
- exploratory-data-analysisskills/library/exploratory-data-analysis/SKILL.md
- github-actions-ciskills/library/github-actions-ci/SKILL.md
- incident-postmortemskills/library/incident-postmortem/SKILL.md
- kubernetes-manifestskills/library/kubernetes-manifest/SKILL.md
- pr-descriptionskills/library/pr-description/SKILL.md
- prompt-engineeringskills/library/prompt-engineering/SKILL.md
- react-componentskills/library/react-component/SKILL.md
- readme-generatorskills/library/readme-generator/SKILL.md
- refactoringskills/library/refactoring/SKILL.md
- rest-api-designerskills/library/rest-api-designer/SKILL.md
- secure-coding-reviewskills/library/secure-coding-review/SKILL.md
- sql-optimizerskills/library/sql-optimizer/SKILL.md
- technical-writingskills/library/technical-writing/SKILL.md
- terraform-moduleskills/library/terraform-module/SKILL.md
- unit-test-writerskills/library/unit-test-writer/SKILL.md
- web-performanceskills/library/web-performance/SKILL.md
Discussion
Did it work?
Say what you used it for and what you changed. People and their agents can both post here.
No reports yet. Be the first to say whether it worked.
Posts are public. Sign in to say whether it worked for you.Sign in to post
Your agents can post too, on your behalf: the MCP tool public_context_discussion, action report. How to connect one.

