threat-modeling-expert
Proactive security architecture review and threat identification tool using STRIDE and PASTA methodologies.
Install
mkdir -p .claude/skills/threat-modeling-expert && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/4039" && unzip -o skill.zip -d .claude/skills/threat-modeling-expert && rm skill.zipInstalls to .claude/skills/threat-modeling-expert
Activation
This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.
Expert in threat modeling methodologies, security architecture review, and risk assessment. Masters STRIDE, PASTA, attack trees, and security requirement extraction. Use PROACTIVELY for security architecture reviews, threat identification, or building secure-by-design systems.Key capabilities
- →Constructs attack trees for critical system paths
- →Performs STRIDE decomposition on data flows
- →Maps mitigations to identified threat vectors
- →Scores risks based on system impact
- →Extracts security requirements from architecture
How it works
Analyzes system architecture and data flows against standardized methodologies like STRIDE to generate a structured risk assessment.
Inputs & outputs
When to use threat-modeling-expert
- →Designing secure system architectures
- →Performing security gap analysis
- →Prioritizing security investments
- →Preparing for security audits
About this skill
Threat Modeling Expert
Expert in threat modeling methodologies, security architecture review, and risk assessment. Masters STRIDE, PASTA, attack trees, and security requirement extraction. Use PROACTIVELY for security architecture reviews, threat identification, or building secure-by-design systems.
Capabilities
- STRIDE threat analysis
- Attack tree construction
- Data flow diagram analysis
- Security requirement extraction
- Risk prioritization and scoring
- Mitigation strategy design
- Security control mapping
Use this skill when
- Designing new systems or features
- Reviewing architecture for security gaps
- Preparing for security audits
- Identifying attack vectors
- Prioritizing security investments
- Creating security documentation
- Training teams on security thinking
Do not use this skill when
- You lack scope or authorization for security review
- You need legal or compliance certification
- You only need automated scanning without human review
Instructions
- Define system scope and trust boundaries
- Create data flow diagrams
- Identify assets and entry points
- Apply STRIDE to each component
- Build attack trees for critical paths
- Score and prioritize threats
- Design mitigations
- Document residual risks
Safety
- Avoid storing sensitive details in threat models without access controls.
- Keep threat models updated after architecture changes.
Best Practices
- Involve developers in threat modeling sessions
- Focus on data flows, not just components
- Consider insider threats
- Update threat models with architecture changes
- Link threats to security requirements
- Track mitigations to implementation
- Review regularly, not just at design time
Limitations
- Use this skill only when the task clearly matches the scope described above.
- Do not treat the output as a substitute for environment-specific validation, testing, or expert review.
- Stop and ask for clarification if required inputs, permissions, safety boundaries, or success criteria are missing.
When not to use it
- →When full architecture access is prohibited
- →Replacing formal compliance auditing services
Prerequisites
Limitations
- →Requires human oversight for validity
- →Model accuracy is limited by the provided design information
- →Not a replacement for authorized compliance certification
How it compares
It produces a structured security architecture analysis based on formal methodologies rather than simple vulnerability scanning.
Compared to similar skills
threat-modeling-expert side by side with the closest alternatives in the catalog.
| Skill | Installs | Updated | Safety | Difficulty |
|---|---|---|---|---|
| threat-modeling-expert (this skill) | 1 | 4mo | No flags | Advanced |
| agent-v3-security-architect | 3 | 6mo | Review | Advanced |
| pytm | 1 | 6mo | Review | Advanced |
| audit-workflow | 0 | 3mo | No flags | Intermediate |
Try saying
Example prompts that trigger this skill in your AI assistant.
More by sickn33
View all by sickn33 →You might also like
agent-v3-security-architect
ruvnet
Agent skill for v3-security-architect - invoke with $agent-v3-security-architect
pytm
rohunj
Python-based threat modeling using pytm library for programmatic STRIDE analysis, data flow diagram generation, and automated security threat identification. Use when: (1) Creating threat models programmatically using Python code, (2) Generating data flow diagrams (DFDs) with automatic STRIDE threat identification, (3) Integrating threat modeling into CI/CD pipelines and shift-left security practices, (4) Analyzing system architecture for security threats across trust boundaries, (5) Producing threat reports with STRIDE categories and mitigation recommendations, (6) Maintaining threat models as code for version control and automation.
audit-workflow
FlorianDrevet
Use when: code audit, technical audit, security audit, performance audit, scalability audit, database audit, audit markdown, GitHub audit issues, findings reconciliation, labels sync.
threat-model
blazengreen360
Hometower's security threat model — architecture trust boundaries, known previously-fixed vulnerabilities, and STRIDE threat lanes mapped to specific files. Read this when performing security audits or reviewing auth/data-handling code.
game-engine-resources
gmh5225
Guide for game engine development resources including engine source code, plugins, and development guides. Use this skill when researching game engines (Unreal, Unity, Godot, custom engines), engine architecture, or game development frameworks.
engineering-skills
alirezarezvani
23 production-ready engineering skills covering architecture, frontend, backend, fullstack, QA, DevOps, security, AI/ML, data engineering, computer vision, and specialized tools like Playwright Pro, Stripe integration, AWS, and MS365. 30+ Python automation tools (all stdlib-only). Works with Claude Code, Codex CLI, and OpenClaw.