Setup & Installation
What This Skill Does
Performs AppSec-grade threat modeling on a specific repository or code path. Maps trust boundaries, assets, entry points, and attacker capabilities, then enumerates concrete abuse paths with likelihood and impact ratings. Outputs a structured Markdown threat model file grounded in evidence from the repo.
Instead of working through a generic STRIDE checklist manually, this skill anchors every threat to actual code paths and components in the repo, so the output reflects your system rather than a template.
When to use it
- Threat modeling a web API before a security review
- Mapping trust boundaries in a multi-service backend
- Identifying abuse paths for file upload or parser endpoints
- Generating a threat model doc for a pentest scope
- Auditing attacker capabilities for an internet-exposed admin interface