# Threat Model Generation

> Generate or refresh a STRIDE-based threat model for the current repository using Bug Hunter-native artifacts. Use whenever the repository has no threat model yet, the architecture changed materially, a security review needs fresh trust-boundary context, or the user explicitly asks for a threat model.

- Skill: `codexstar69/threat-model-generation` (Agent Skill)
- Install (CLI): `npx skillmds@latest add codexstar69/threat-model-generation`
- Raw SKILL.md: https://api.skillmd.com/api/skills/codexstar69/threat-model-generation/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: AI & ML
- Author: codexstar69 (https://skillmd.com/u/codexstar69)
- Updated: 2026-09-09
- Page: https://skillmd.com/skills/codexstar69/threat-model-generation

---


# Threat Model Generation

This is a bundled local Bug Hunter companion skill. It generates portable threat-model artifacts under `.bug-hunter/`.

## Purpose

Create the security context that the other security skills depend on:
- trust boundaries
- major components
- STRIDE threats
- vulnerability pattern library
- severity/config defaults

## Required outputs

Write:
- `.bug-hunter/threat-model.md`
- `.bug-hunter/security-config.json`

## Workflow

1. Read `.bug-hunter/triage.json` if available for file structure and domain hints.
2. Inspect the repository to identify:
   - languages and frameworks
   - public/authenticated/internal entry points
   - data stores and external integrations
   - sensitive assets and trust boundaries
3. Generate a concise STRIDE threat model.
4. Generate a matching security config with thresholds and tech-stack metadata.

## Compatibility

`prompts/threat-model.md` is generated from this skill for older clients. This
skill is the canonical source and must be edited instead of the generated
compatibility prompt.

## Output rules

- Keep the threat model short enough for downstream agents to consume.
- Be specific about trust boundaries and vulnerable code patterns.
- Keep all artifacts under `.bug-hunter/`, never `.factory/`.

