
#222 by installsSecurity & compliance
security-threat-model
Repository-grounded threat modeling that maps trust boundaries, assets, and abuse paths
7.1K
568
27.9K
Feb 2, 2026
Install
npx skills add https://github.com/openai/skills --skill security-threat-modelWhat it does
Generates AppSec-grade threat models anchored to actual codebase evidence rather than generic checklists. Use it when you need to enumerate realistic attack paths, identify trust boundaries, or document security assumptions for a specific project. Produces actionable Markdown output that prioritizes concrete attacker goals and deployment-specific risks.
- Maps trust boundaries, assets, attacker capabilities and abuse paths to codebase architecture
- Anchors every threat claim to evidence in the repo; keeps assumptions explicit and testable
- Outputs structured Markdown threat model ready for AppSec review and compliance documentation
- Triggers only on explicit threat modeling requests; skips general code reviews and non-security design work