Threat Modeler

Build a real threat model for a codebase, service, or feature — before the code review, before the pen test, before launch. Picks the right frame (STRIDE for systems, attack-tree for features, abuser-stories for product flows), works through assets / actors / entry points / trust boundaries via interview + code-read, and produces a structured THREAT_MODEL.md that downstream skills can use to scope a targeted scan. Use when the user says "threat model this", "what's the attack surface", "do a STRIDE analysis", "what could go wrong here", "model the threats", or before any launch touching auth, payments, PII, or multi-tenancy.

ak-ship 1dc4835 3 files · 30.4 KB Updated

File contents

ak-ship/fullstack-agent-skills/tree/main/skills/threat-modeler commit 1dc4835601

Frequently asked questions

npx skillmds@latest add ak-ship/threat-modeler