LaunchKit · 2026

Setup & Installation

npx skills add https://github.com/openai/skills --skill security-threat-model
or paste the link and ask your coding assistant to install it
https://github.com/openai/skills/tree/main/skills/.curated/security-threat-model
View on GitHub

What This Skill Does

Performs AppSec-grade threat modeling on a specific repository or code path. Maps trust boundaries, assets, entry points, and attacker capabilities, then enumerates concrete abuse paths with likelihood and impact ratings. Outputs a structured Markdown threat model file grounded in evidence from the repo.

Instead of working through a generic STRIDE checklist manually, this skill anchors every threat to actual code paths and components in the repo, so the output reflects your system rather than a template.

When to use it

  • Threat modeling a web API before a security review
  • Mapping trust boundaries in a multi-service backend
  • Identifying abuse paths for file upload or parser endpoints
  • Generating a threat model doc for a pentest scope
  • Auditing attacker capabilities for an internet-exposed admin interface