Threat Model Builder
$2.99OfficialUse when designing or changing a feature and you need a STRIDE threat model: map the system, enumerate threats per element, and rank mitigations.
securitysecuritythreat-modelingstridedesign-reviewarchitectureriskยท by SkillingMain
What you get
- โ10-step procedure
- โ1 ready-to-run code block
- โ10-point quality checklist
- โ10 pitfalls to avoid
- โInstalls into 6 tools
- Version
- v1 โ
- Last updated
- today
- Length
- 8 min read
- Requires
- Best with a strong model (Claude Sonnet 4)
Works in: Claude Code, Codex, Cline, opencode, OpenClaw, Hermes ยท Handles multi-file projects
Preview
When to use
Invoke before or during design, when the question is what could go wrong rather than what is broken. Typical triggers:
- A feature adds an entry point, a trust boundary, a data store, or a third-party integration.
- A design document or RFC needs a security section before approval.
- An authentication, authorization, payment, or tenancy model is being changed.
- A penetration test needs scoping, or an auditor asks for a documented model.
- A post-incident review asks whether the failing class was ever considered.
Use a code audit skill instead when the code already exists and the goal is to find concrete defects.
Inputs to gather
- The design: the document, diagram
โฆ
๐ Buy once ($2.99) to unlock the full playbook, download it, and install it in every tool you use.