security-threat-model
Repository-grounded threat modeling that enumerates trust boundaries, assets, attacker capabilities, abuse paths, and mitigations, and writes a concise Markdown threat model. Trigger only when the user explicitly asks to threat model a codebase or path, enumerate threats/abuse paths, or perform AppSec threat modeling. Do not trigger for general architecture summaries, code review, or non-security design work.
npx skills add waybarrios/opencode-power-pack --skill security-threat-model --agent claude-code
Same command for any agent — swap --agent for codex, cursor, copilot.
Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.
# Threat Model Source Code Repo Deliver an actionable AppSec-grade threat model that is specific to the repository or a project path, not a generic checklist. Anchor every architectural claim to evidence in the repo and keep assumptions explicit. Prioritizing realistic attacker goals and concrete impacts over generic checklists. ## Quick start 1) Collect (or infer) inputs: - Repo root path and any in-scope paths. - Intended usage, deployment model, internet exposure, and auth expectations (if known). - Any existing repository summary or architecture spec. - Use prompts in `references/prompt-template.md` to generate a repository summary. - Follow the required output contract in `references/prompt-template.md`. Use it verbatim when possible. ## Workflow ### 1) Scope and extract the system model - Identify primary components, data stores, and external integrations from the repo summary. - Identify how the system runs (server, CLI, library, worker) and its entrypoints. - Separate runtime behavior from CI/build/dev tooling and from tests/examples. - Map the in-scope locations to those components and exclude out-of-scope items explicitly. - Do not claim components, flows, or controls wit
- Quick start
- Workflow
- 1) Scope and extract the system model
- 2) Derive boundaries, assets, and entry points
- 3) Calibrate assets and attacker capabilities
- 4) Enumerate threats as abuse paths
- 5) Prioritize with explicit likelihood and impact reasoning
- 6) Validate service context and assumptions with the user
- 7) Recommend mitigations and focus paths
- 8) Run a quality check before finalizing
- Risk prioritization guidance (illustrative, not exhaustive)
- References
What does the security-threat-model skill do?
Repository-grounded threat modeling that enumerates trust boundaries, assets, attacker capabilities, abuse paths, and mitigations, and writes a concise Markdown threat model. Trigger only when the user explicitly asks to threat model a codebase or path, enumerate threats/abuse paths, or perform AppSec threat modeling. Do not trigger for general architecture summaries, code review, or non-security design work.
How do I install it?
Run `npx skills add waybarrios/opencode-power-pack --skill security-threat-model --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.
Where does this skill come from?
From waybarrios/opencode-power-pack, a repository with 443 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.
Is a popular skill a good skill?
Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.