Expert in threat modeling methodologies, security architecture review, and risk assessment. Masters STRIDE, PASTA, attack trees, and security requirement extraction. Use PROACTIVELY for security architecture reviews, threat identification, or building secure-by-design systems.
Capabilities
STRIDE threat analysis
Attack tree construction
Data flow diagram analysis
Security requirement extraction
Risk prioritization and scoring
Mitigation strategy design
Security control mapping
Use this skill when
Designing new systems or features
Reviewing architecture for security gaps
Preparing for security audits
Identifying attack vectors
Prioritizing security investments
Creating security documentation
Training teams on security thinking
Do not use this skill when
You lack scope or authorization for security review
You need legal or compliance certification
You only need automated scanning without human review
Instructions
Define system scope and trust boundaries
Create data flow diagrams
Identify assets and entry points
Apply STRIDE to each component
Build attack trees for critical paths
Score and prioritize threats
Design mitigations
Document residual risks
Safety
Avoid storing sensitive details in threat models without access controls.
Keep threat models updated after architecture changes.
Best Practices
Involve developers in threat modeling sessions
Focus on data flows, not just components
Consider insider threats
Update threat models with architecture changes
Link threats to security requirements
Track mitigations to implementation
Review regularly, not just at design time
1---2name: threat-modeling-expert3description: Threat Modeling Expert4---5# Threat Modeling Expert67Expert in threat modeling methodologies, security architecture review, and risk assessment. Masters STRIDE, PASTA, attack trees, and security requirement extraction. Use PROACTIVELY for security architecture reviews, threat identification, or building secure-by-design systems.89## Capabilities1011- STRIDE threat analysis12- Attack tree construction13- Data flow diagram analysis14- Security requirement extraction15- Risk prioritization and scoring16- Mitigation strategy design17- Security control mapping1819## Use this skill when2021- Designing new systems or features22- Reviewing architecture for security gaps23- Preparing for security audits24- Identifying attack vectors25- Prioritizing security investments26- Creating security documentation27- Training teams on security thinking2829## Do not use this skill when3031- You lack scope or authorization for security review32- You need legal or compliance certification33- You only need automated scanning without human review3435## Instructions36371. Define system scope and trust boundaries382. Create data flow diagrams393. Identify assets and entry points404. Apply STRIDE to each component415. Build attack trees for critical paths426. Score and prioritize threats437. Design mitigations448. Document residual risks4546## Safety4748- Avoid storing sensitive details in threat models without access controls.49- Keep threat models updated after architecture changes.5051## Best Practices5253- Involve developers in threat modeling sessions54- Focus on data flows, not just components55- Consider insider threats56- Update threat models with architecture changes57- Link threats to security requirements58- Track mitigations to implementation59- Review regularly, not just at design time
Run npx skillmds@latest add comeonoliver/threat-modeling-expert in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.
Threat Modeling Expert It is listed under Security on SkillMD.
This skill has not completed SkillMD's automated safety review yet. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.
This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.
Yes. Installing skills from SkillMD is free, and the skill stays under its author's original license.
ComeOnOliver (@comeonoliver) published this skill. Their other Agent Skills are listed on their SkillMD profile.