threat-modeling-expert
Model Security Threats with STRIDE
Security reviews can miss abuse paths, trust boundaries, and residual risks. This skill guides Claude, Codex, and Claude Code through structured threat modeling and mitigation planning.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "threat-modeling-expert" from https://skillstore.io/skills/sickn33-threat-modeling-expert.md and its manifest at https://skillstore.io/api/skills/sickn33-threat-modeling-expert/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "threat-modeling-expert". A team describes a payment API with external users, webhook callbacks, and admin access.
Expected outcome:
A STRIDE threat summary covering spoofing, tampering, replay, authorization, logging, and rate limit recommendations.
Using "threat-modeling-expert". An architect shares data flows for a new document processing service.
Expected outcome:
A prioritized list of threats, trust boundary concerns, required controls, and residual risk notes.
Using "threat-modeling-expert". A security lead provides critical workflows for account recovery.
Expected outcome:
Attack tree narratives that show attacker goals, likely paths, mitigations, and remaining review questions.
Security Audit
SafeThe static finding at SKILL.md line 49 is a false positive. The line warns users not to store sensitive threat model details without access controls, which is safety guidance. No prompt injection, exfiltration intent, or abusive workflow guidance was found in SKILL.md.
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/sickn33-threat-modeling-expert/audits/5?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/sickn33-threat-modeling-expert?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/sickn33-threat-modeling-expert?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/sickn33-threat-modeling-expert/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/sickn33-threat-modeling-expert.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA · BibTeX · CFF)
APA citation
sickn33. (2026). threat-modeling-expert security audit report (audit version 5) [Author version unspecified]. Skillstore. https://skillstore.io/skills/sickn33-threat-modeling-expert/audits/5BibTeX citation
@techreport{sickn33-sickn33-threat-modeling-expert-2026,
author = {sickn33},
title = {threat-modeling-expert security audit report (audit version 5)},
institution = {Skillstore},
year = {2026},
number = {5},
url = {https://skillstore.io/skills/sickn33-threat-modeling-expert/audits/5},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "threat-modeling-expert security audit report (audit version 5)"
version: "unspecified"
type: report
authors:
- name: "sickn33"
date-released: "2026-07-07"
url: "https://skillstore.io/skills/sickn33-threat-modeling-expert/audits/5"
identifiers:
- type: other
value: "skillstore:sickn33-threat-modeling-expert:audit:5"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: HighWhat You Can Build
Design New Architecture
Identify threats before implementation by mapping data flows, trust boundaries, assets, and required controls.
Prepare Product Reviews
Turn feature plans into prioritized threats, mitigations, and residual risk notes for review meetings.
Improve Audit Readiness
Document security assumptions, control mappings, and open risks before an internal or external assessment.
Try These Prompts
Help me threat model this system. Ask me for scope, users, assets, data flows, trust boundaries, and deployment details before analysis.
Apply STRIDE to these components and data flows: [paste architecture]. List threats, affected assets, assumptions, and missing context.
Build attack trees for these critical workflows: [paste workflows]. Include attacker goals, prerequisites, paths, mitigations, and residual risk.
Review this threat list and proposed mitigations. Rank risks, map controls, identify gaps, and produce security requirements for engineering.
Best Practices
- Bring current architecture diagrams, data flow details, and deployment assumptions into each session.
- Record assumptions, owners, mitigations, due dates, and residual risks in the final model.
- Update the threat model when components, data stores, trust boundaries, or access patterns change.
Avoid
- Using threat modeling as a one-time checklist after implementation is complete.
- Listing generic threats without tying them to assets, data flows, or controls.
- Adding sensitive credentials, secrets, or customer data to shared threat model documents.
Frequently Asked Questions
Does this skill run security scans?
Which methodologies does it support?
What information should I provide?
Can it replace a security review?
Can it help with existing systems?
Is it safe for sensitive systems?
Developer Details
Author
sickn33License
MIT
Skillstore revision
r1
Version notice
The author did not declare a version.
Repository
https://github.com/sickn33/antigravity-awesome-skills/tree/main/skills/threat-modeling-expertRef
9f814fc6a43fd99946f2da5e0df231c65a38bc76
Maintenance freshness
7/18/2026
Usage
8 downloads · 70 views
File structure
📄 SKILL.md