Threat Modeling

Use when: systematically identify threats to a system and decide how to mitigate them.

kimtth dc668b2 1.0 KB Updated

File contents

Goal: understand what can go wrong before it does, and plan mitigations.

Use for:

  • designing a new feature or system with security in mind
  • finding attack surfaces and abuse cases
  • prioritizing security work by risk

Workflow:

  1. Diagram the system: components, data flows, and trust boundaries.
  2. Identify assets worth protecting and who might attack them.
  3. Enumerate threats per element (e.g. with STRIDE).
  4. Rate each by likelihood and impact.
  5. Decide to mitigate, accept, transfer, or eliminate.
  6. Track mitigations as concrete, testable work.

STRIDE prompts:

  • Spoofing, Tampering, Repudiation
  • Information disclosure, Denial of service
  • Elevation of privilege

Rules:

  • model around data flows and trust boundaries
  • focus effort on high-likelihood, high-impact threats
  • record accepted risks explicitly, with rationale
  • turn mitigations into verifiable tasks, not intentions

kimtth/agent-skill-100-lines-or-less/tree/main/skills/threat-modeling commit dc668b29c9

Frequently asked questions

npx skillmds@latest add kimtth/threat-modeling