# Openclaw 0431 Attack Surface Modeling

> PublicService Security Threat Modeler. Use when work requires attack-surface modeling for Healthcare and Public Services with guardrails, traceable execution, and measurable outcomes.

- Skill: `zwright8/openclaw-0431-attack-surface-modeling` (Agent Skill, multi-file: 3 files)
- Install (CLI): `npx skillmds add zwright8/openclaw-0431-attack-surface-modeling`
- Raw SKILL.md: https://api.skillmd.com/api/skills/zwright8/openclaw-0431-attack-surface-modeling/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Security
- Author: zwright8 (https://skillmd.com/u/zwright8)
- Updated: 2026-09-10
- Page: https://skillmd.com/skills/zwright8/openclaw-0431-attack-surface-modeling

---


# PublicService Security Threat Modeler

## Mission
We need this skill because public-facing workflows require strict safety and reliability controls. This specific skill anticipates attack paths before adversaries exploit them.

## Activation Cues
- Task requires attack-surface modeling in Healthcare and Public Services.
- Task needs explicit risk controls, approval gates, and traceable outcomes.
- Task output must include artifact handoff for humans and agents.

## Execution Plan
1. Define the scope and success metrics for `PublicService Security Threat Modeler`, including at least three measurable KPIs tied to service harm and procedural violations.
2. Design and version the input/output contract for protocol checks, service queues, and compliance flags, then add schema validation and failure-mode handling.
3. Implement the core capability using attack-surface modeling, and produce threat models with deterministic scoring.
4. Integrate the skill into swarm orchestration: task routing, approval gates, retry strategy, and rollback controls.
5. Add unit, integration, and simulation tests that explicitly cover service harm and procedural violations, then run regression baselines.
6. Deploy behind a feature flag, monitor telemetry/alerts for two release cycles, and iterate thresholds based on observed outcomes.

## Runbook
Preflight:
- None specified.

Execution:
- None specified.

Recovery:
- None specified.

Handoff:
- None specified.

## Guardrails
- [quality] Require validations before promoting outputs.

## Success Metrics
- Primary metric: service harm
- Secondary metrics: procedural violations, decision drift
- Review cadence: weekly

## Output Contract
- Return a concise execution summary with key decisions.
- Return risk and mitigation notes with unresolved blockers.
- Return artifact target: `threat models`.
- Return recommended follow-up tasks for next wave execution.

