Threat Modeling

Design-time security analysis of a system or feature before it's built — trust boundaries, attack surface, STRIDE per element, abuse cases, prioritized mitigations that become security requirements. Triggers: threat model, STRIDE, trust boundary, attack surface, what could go wrong security-wise, security design review, abuse case, secure this design, security requirements. Reviewing EXISTING code/config for vulnerabilities → security-audit; use this skill while the design is still on the whiteboard.

SWEStash 9a83792 3 files · 14.0 KB Updated

File contents

SWEStash/swe-workflow-skills/tree/main/skills/threat-modeling commit 9a83792ec4

Frequently asked questions

npx skillmds@latest add swestash/threat-modeling