Agent skill

threat-modeling

Conduct threat modeling using STRIDE methodology. Identify threats, assess risks, and design security controls. Use when designing secure systems or assessing application security.

Stars 163
Forks 31

Install this agent skill to your Project

npx add-skill https://github.com/majiayu000/claude-skill-registry/tree/main/skills/other/other/threat-modeling

Metadata

Additional technical details for this skill

author
devops-skills
version
1.0

SKILL.md

Threat Modeling

Identify and mitigate security threats during system design.

STRIDE Methodology

Threat Description Mitigation
Spoofing Pretending to be someone else Authentication
Tampering Modifying data Integrity controls
Repudiation Denying actions Audit logging
Information Disclosure Data exposure Encryption
Denial of Service Making service unavailable Rate limiting
Elevation of Privilege Gaining higher access Authorization

Process

yaml
steps:
  1_scope:
    - Define system boundaries
    - Identify assets
    - Document data flows
    
  2_diagram:
    - Create data flow diagrams
    - Identify trust boundaries
    - Mark entry points
    
  3_identify:
    - Apply STRIDE to each component
    - List potential threats
    - Document attack vectors
    
  4_assess:
    - Rate likelihood and impact
    - Prioritize by risk score
    
  5_mitigate:
    - Design countermeasures
    - Accept/transfer risks
    - Document decisions

Data Flow Diagram

[External User] --> |HTTPS| --> [Load Balancer]
                                      |
                                      v
                               [Web Server]
                                      |
                              [Trust Boundary]
                                      |
                                      v
                                [App Server] --> [Database]

Threat Cards

yaml
threat:
  id: T001
  name: SQL Injection
  category: Tampering
  component: Database queries
  likelihood: High
  impact: Critical
  mitigations:
    - Parameterized queries
    - Input validation
    - WAF rules
  status: Mitigated

Best Practices

  • Integrate into SDLC
  • Review on architecture changes
  • Include development team
  • Document all decisions
  • Regular reassessment

Related Skills

  • sast-scanning - Code analysis
  • penetration-testing - Validation

Expand your agent's capabilities with these related and highly-rated skills.

Didn't find tool you were looking for?

Be as detailed as possible for better results