# Threat Surface Mapping

> Enumerate all attackable surfaces of an artifact — logical, empirical, methodological, social, and practical dimensions.

- Skill: `yogsoth-ai/threat-surface-mapping` (Agent Skill, multi-file: 2 files)
- Install (CLI): `npx skillmds@latest add yogsoth-ai/threat-surface-mapping`
- Raw SKILL.md: https://api.skillmd.com/api/skills/yogsoth-ai/threat-surface-mapping/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Security
- Author: yogsoth-ai (https://skillmd.com/u/yogsoth-ai)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/yogsoth-ai/threat-surface-mapping

---


# Threat Surface Mapping

Enumerates all surfaces of the artifact that could be attacked or challenged.

## Execution

Subagent — spawned via subagent-spawning/spawn-agent.

## Why Subagent

Surface enumeration requires systematic coverage without bias toward obvious attack points. Isolated context prevents premature focus on specific vulnerabilities.

## Input

- **artifact**: The complete artifact to analyze
- **artifact_type**: Type of artifact (hypothesis, claim, idea, approach, etc.)

## Output

- **surfaces**: List of threat surfaces with category, description, and attack accessibility rating
- **coverage_map**: Matrix of dimensions covered vs. uncovered
- **priority_ranking**: Surfaces ranked by expected vulnerability

<!-- BEGIN available-tables (generated) -->

## Available SOPs

Optional, no fixed order; the final leaf is always a sop.

| SOP | When to use |
| --- | --- |
| spawn-agent | Spawn a customized CC subagent with full MCP tool access. Used by SOPs that declare execution: subagent. |

<!-- END available-tables (generated) -->

