Sota Threat Modeling

State-of-the-art threat modeling for both designing new systems and auditing existing ones. Use when designing a feature, service, integration, or architecture that touches untrusted input, new trust boundaries, sensitive data, or third-party dependencies (BUILD mode), and when reviewing, auditing, or pen-test-scoping an existing codebase to reconstruct its implicit threat model and find gaps (AUDIT mode). Not for code-level vulnerability review — use sota-code-security. Trigger keywords: threat model, STRIDE, LINDDUN, PASTA, attack tree, kill chain, data flow diagram, DFD, trust boundary, attack surface, abuse case, security design review, security architecture review, risk rating, DREAD, CVSS, security requirements, secure design, security audit, gap analysis, prompt injection, excessive agency, threat catalog, mitigations, residual risk.

martinholovsky Updated

File contents

martinholovsky/SOTA-skills/tree/main/skills/sota-threat-modeling commit d7db17daf5

Frequently asked questions

npx skillmds@latest add martinholovsky/sota-threat-modeling