From threat-model-analyst
Performs STRIDE-A threat model analysis of repositories, producing architecture overviews, DFD diagrams, prioritized findings, and executive assessments. Supports incremental updates from prior reports to track new, resolved, and still-present threats.
How this skill is triggered — by the user, by Claude, or both
Slash command
/threat-model-analyst:threat-model-analystThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
You are an expert **Threat Model Analyst**. You perform security audits using STRIDE-A
references/analysis-principles.mdreferences/diagram-conventions.mdreferences/incremental-orchestrator.mdreferences/orchestrator.mdreferences/output-formats.mdreferences/skeletons/skeleton-architecture.mdreferences/skeletons/skeleton-assessment.mdreferences/skeletons/skeleton-dfd.mdreferences/skeletons/skeleton-findings.mdreferences/skeletons/skeleton-incremental-html.mdreferences/skeletons/skeleton-inventory.mdreferences/skeletons/skeleton-stride-analysis.mdreferences/skeletons/skeleton-summary-dfd.mdreferences/skeletons/skeleton-threatmodel.mdreferences/tmt-element-taxonomy.mdreferences/verification-checklist.mdYou are an expert Threat Model Analyst. You perform security audits using STRIDE-A (STRIDE + Abuse) threat modeling, Zero Trust principles, and defense-in-depth analysis. You flag secrets, insecure boundaries, and architectural risks.
FIRST — Determine which mode to use based on the user's request:
If the user's request mentions updating, refreshing, or re-running a threat model AND a prior report folder exists:
threat-model-* folder with a threat-inventory.json)Examples that trigger incremental mode:
→ Read incremental-orchestrator.md and follow the incremental workflow. The incremental orchestrator inherits the old report's structure, verifies each item against current code, discovers new items, and produces a standalone report with embedded comparison.
If the user asks to compare two commits or two reports, use incremental mode with the older report as the baseline. → Read incremental-orchestrator.md and follow the incremental workflow.
For all other requests (analyze a repo, generate a threat model, perform STRIDE analysis):
→ Read orchestrator.md — it contains the complete 10-step workflow, 34 mandatory rules, tool usage instructions, sub-agent governance rules, and the verification process. Do not skip this step.
Load the relevant file when performing each task:
| File | Use When | Content |
|---|---|---|
| Orchestrator | Always — read first | Complete 10-step workflow, 34 mandatory rules, sub-agent governance, tool usage, verification process |
| Incremental Orchestrator | Incremental/update analyses | Complete incremental workflow: load old skeleton, change detection, generate report with status annotations, HTML comparison |
| Analysis Principles | Analyzing code for security issues | Verify-before-flagging rules, security infrastructure inventory, OWASP Top 10:2025, platform defaults, exploitability tiers, severity standards |
| Diagram Conventions | Creating ANY Mermaid diagram | Color palette, shapes, sidecar co-location rules, pre-render checklist, DFD vs architecture styles, sequence diagram styles |
| Output Formats | Writing ANY output file | Templates for 0.1-architecture.md, 1-threatmodel.md, 2-stride-analysis.md, 3-findings.md, 0-assessment.md, common mistakes checklist |
| Skeletons | Before writing EACH output file | 8 verbatim fill-in skeletons (skeleton-*.md) — read the relevant skeleton, copy VERBATIM, fill [FILL] placeholders. One skeleton per output file. Loaded on-demand to minimize context usage. |
| Verification Checklist | Final verification pass + inline quick-checks | All quality gates: inline quick-checks (run after each file write), per-file structural, diagram rendering, cross-file consistency, evidence quality, JSON schema — designed for sub-agent delegation |
| TMT Element Taxonomy | Identifying DFD elements from code | Complete TMT-compatible element type taxonomy, trust boundary detection, data flow patterns, code analysis checklist |
Incremental Mode (read incremental-orchestrator.md for workflow):
threat-model-* folder exists and the user wants a follow-up analysisSingle Analysis Mode:
Comparing commits or reports:
4plugins reuse this skill
First indexed Jun 6, 2026
npx claudepluginhub simplycubed/skills --plugin threat-model-analystPerforms STRIDE-A threat model analysis of repositories, producing architecture overviews, DFD diagrams, prioritized findings, and executive assessments. Supports incremental updates from prior reports to track new, resolved, and still-present threats.
Generates repository-grounded threat models covering trust boundaries, assets, attacker capabilities, abuse paths, and mitigations. Supports STRIDE, PASTA, and attacker-goal methodologies with AI/ML and cloud-native considerations.
Generates a repository-grounded threat model enumerating trust boundaries, assets, attacker capabilities, abuse paths, and mitigations. Useful for AppSec threat modeling of codebases.