Source profileQuality 76/100

github/awesome-copilot/skills/threat-model-analyst/SKILL.md

threat-model-analyst

Full STRIDE-A threat model analysis and incremental update skill for repositories and systems. Supports two modes: (1) Single analysis — full STRIDE-A threat model of a repository, producing architecture overviews, DFD diagrams, STRIDE-A analysis, prioritized findings, and executive assessments. (2) Incremental analysis — takes a previous threat model report as baseline, compares the codebase at the latest (or a given commit), and produces an updated report with change tracking (new, resolved, s

Source repository stars
37,126
Declared platforms
0
Static risk flags
2
Last source update
2026-07-28
Source checked
2026-07-28

Decision brief

What it does—and where it fits

You are an expert Threat Model Analyst. You perform security audits using STRIDE-A (STRIDE + Abuse) threat modeling, Zero Trust principles, and defense-in-depth analysis. You flag secrets, insecure boundaries, and architectural risks.

Best for

    Not for

    • Tasks that require unconfirmed production actions or broad system permissions.
    • Environments where the pinned source and install steps cannot be inspected.

    Compatibility matrix

    Platform support, with evidence labels

    PlatformStatusEvidenceWhat to check
    CodexNot declaredNo explicit evidencePortability before use
    Claude CodeNot declaredNo explicit evidencePortability before use
    CursorNot declaredNo explicit evidencePortability before use
    Gemini CLINot declaredNo explicit evidencePortability before use
    Open the compatibility checker

    Installation

    Inspect first. Install second.

    The source command is displayed only when detected. A safe inspection prompt is always available so your agent can explain every action before execution.

    Source-detected install commandSource
    npx skills add https://github.com/github/awesome-copilot --skill "skills/threat-model-analyst"
    Safe inspection promptEditorial

    Inspect the Agent Skill "threat-model-analyst" from https://github.com/github/awesome-copilot/blob/9933dcad5be5caeb288cebcd370eeeb2fc2f1685/skills/threat-model-analyst/SKILL.md at commit 9933dcad5be5caeb288cebcd370eeeb2fc2f1685. List every install step, command, network request, credential, file read/write, external action, and rollback step. Explain whether it fits my task. Do not install or execute anything until I approve.

    Workflow

    What the source asks the agent to do

    1. 01

      Getting Started

      FIRST — Determine which mode to use based on the user's request:

      Action words: "update", "refresh", "re-run", "incremental", "what changed", "since last analysis"AND a baseline report folder is identified (either explicitly named or auto-detected as the most recent threat-model- folder with a threat-inventory.json)OR the user explicitly provides a baseline report folder + a target commit/HEAD
    2. 02

      Incremental Mode (Preferred for Follow-Up Analyses)

      If the user's request mentions updating, refreshing, or re-running a threat model AND a prior report folder exists: - Action words: "update", "refresh", "re-run", "incremental", "what changed", "since last analysis" - AND a baseline report folder is identified (either explicitly…

      Action words: "update", "refresh", "re-run", "incremental", "what changed", "since last analysis"AND a baseline report folder is identified (either explicitly named or auto-detected as the most recent threat-model- folder with a threat-inventory.json)OR the user explicitly provides a baseline report folder + a target commit/HEAD
    3. 03

      Comparing Commits or Reports

      If the user asks to compare two commits or two reports, use incremental mode with the older report as the baseline. → Read incremental-orchestrator.md and follow the incremental workflow.

      If the user asks to compare two commits or two reports, use incremental mode with the older report as the baseline. → Read incremental-orchestrator.md and follow the incremental workflow.
    4. 04

      Single Analysis Mode

      For all other requests (analyze a repo, generate a threat model, perform STRIDE analysis):

      For all other requests (analyze a repo, generate a threat model, perform STRIDE analysis):→ Read orchestrator.md — it contains the complete 10-step workflow, 34 mandatory rules, tool usage instructions, sub-agent governance rules, and the verification process. Do not skip this step.
    5. 05

      Reference Files

      Load the relevant file when performing each task:

      Load the relevant file when performing each task:

    Permission review

    Static risk signals and limitations

    Reads files

    low · line 40

    The documentation asks the agent to read local files, directories, or repositories.

    Load the relevant file when performing each task:

    Writes files

    medium · line 50

    The documentation asks the agent to create, modify, or delete local files.

    | [Verification Checklist](./references/verification-checklist.md) | Final verification pass + inline quick-checks | All quality gates: inline quick-checks (run after each file write), per-file structural, diagram rendering, cross-file cons

    Evidence record

    Why each signal appears

    EvidenceSourceComputedTestedEditorial
    SignalValueEvidence typeMeaning
    Quality score76/100ComputedDocumentation, specificity, maintenance, and trust rules
    Repository stars37,126SourceRepository attention, not individual Skill quality
    Compatibility0 platformsSourceDeclared in the catalog source record
    Usage guideautomated source guideEditorialGenerated or reviewed according to the visible evidence level

    Pinned source

    Provenance and original SKILL.md

    Repository
    github/awesome-copilot
    Skill path
    skills/threat-model-analyst/SKILL.md
    Commit
    9933dcad5be5caeb288cebcd370eeeb2fc2f1685
    License
    MIT
    Collected
    2026-07-28
    Default branch
    main
    View the original SKILL.md

    Threat Model Analyst

    You are an expert Threat Model Analyst. You perform security audits using STRIDE-A (STRIDE + Abuse) threat modeling, Zero Trust principles, and defense-in-depth analysis. You flag secrets, insecure boundaries, and architectural risks.

    Getting Started

    FIRST — Determine which mode to use based on the user's request:

    Incremental Mode (Preferred for Follow-Up Analyses)

    If the user's request mentions updating, refreshing, or re-running a threat model AND a prior report folder exists:

    • Action words: "update", "refresh", "re-run", "incremental", "what changed", "since last analysis"
    • AND a baseline report folder is identified (either explicitly named or auto-detected as the most recent threat-model-* folder with a threat-inventory.json)
    • OR the user explicitly provides a baseline report folder + a target commit/HEAD

    Examples that trigger incremental mode:

    • "Update the threat model using threat-model-20260309-174425 as the baseline"
    • "Run an incremental threat model analysis"
    • "Refresh the threat model for the latest commit"
    • "What changed security-wise since the last threat model?"

    → Read incremental-orchestrator.md and follow the incremental workflow. The incremental orchestrator inherits the old report's structure, verifies each item against current code, discovers new items, and produces a standalone report with embedded comparison.

    Comparing Commits or Reports

    If the user asks to compare two commits or two reports, use incremental mode with the older report as the baseline. → Read incremental-orchestrator.md and follow the incremental workflow.

    Single Analysis Mode

    For all other requests (analyze a repo, generate a threat model, perform STRIDE analysis):

    → Read orchestrator.md — it contains the complete 10-step workflow, 34 mandatory rules, tool usage instructions, sub-agent governance rules, and the verification process. Do not skip this step.

    Reference Files

    Load the relevant file when performing each task:

    FileUse WhenContent
    OrchestratorAlways — read firstComplete 10-step workflow, 34 mandatory rules, sub-agent governance, tool usage, verification process
    Incremental OrchestratorIncremental/update analysesComplete incremental workflow: load old skeleton, change detection, generate report with status annotations, HTML comparison
    Analysis PrinciplesAnalyzing code for security issuesVerify-before-flagging rules, security infrastructure inventory, OWASP Top 10:2025, platform defaults, exploitability tiers, severity standards
    Diagram ConventionsCreating ANY Mermaid diagramColor palette, shapes, sidecar co-location rules, pre-render checklist, DFD vs architecture styles, sequence diagram styles
    Output FormatsWriting ANY output fileTemplates for 0.1-architecture.md, 1-threatmodel.md, 2-stride-analysis.md, 3-findings.md, 0-assessment.md, common mistakes checklist
    SkeletonsBefore writing EACH output file8 verbatim fill-in skeletons (skeleton-*.md) — read the relevant skeleton, copy VERBATIM, fill [FILL] placeholders. One skeleton per output file. Loaded on-demand to minimize context usage.
    Verification ChecklistFinal verification pass + inline quick-checksAll quality gates: inline quick-checks (run after each file write), per-file structural, diagram rendering, cross-file consistency, evidence quality, JSON schema — designed for sub-agent delegation
    TMT Element TaxonomyIdentifying DFD elements from codeComplete TMT-compatible element type taxonomy, trust boundary detection, data flow patterns, code analysis checklist

    When to Activate

    Incremental Mode (read incremental-orchestrator.md for workflow):

    • Update or refresh an existing threat model analysis
    • Generate a new analysis that builds on a prior report's structure
    • Track what threats/findings were fixed, introduced, or remain since a baseline
    • When a prior threat-model-* folder exists and the user wants a follow-up analysis

    Single Analysis Mode:

    • Perform full threat model analysis of a repository or system
    • Generate threat model diagrams (DFD) from code
    • Perform STRIDE-A analysis on components and data flows
    • Validate security control implementations
    • Identify trust boundary violations and architectural risks
    • Write prioritized security findings with CVSS 4.0 / CWE / OWASP mappings

    Comparing commits or reports:

    • To compare security posture between commits, use incremental mode with the older report as baseline

    Alternatives

    Compare before choosing

    Computed 10042,015

    coreyhaines31/marketingskills

    ab-testing

    When the user wants to plan, design, or implement an A/B test or experiment, or build a growth experimentation program. Also use when the user mentions "A/B test," "split test," "experiment," "test this change," "variant copy," "multivariate test," "hypothesis," "should I test this," "which version is better," "test two versions," "statistical significance," "how long should I run this test," "growth experiments," "experiment velocity," "experiment backlog," "ICE score," "experimentation program

    Computed 10042,015

    coreyhaines31/marketingskills

    churn-prevention

    When the user wants to reduce churn, build cancellation flows, set up save offers, recover failed payments, or implement retention strategies. Also use when the user mentions 'churn,' 'cancel flow,' 'offboarding,' 'save offer,' 'dunning,' 'failed payment recovery,' 'win-back,' 'retention,' 'exit survey,' 'pause subscription,' 'involuntary churn,' 'people keep canceling,' 'churn rate is too high,' 'how do I keep users,' or 'customers are leaving.' Use this whenever someone is losing subscribers o

    Computed 997

    event4u-app/agent-config

    design-review

    Use when the user says "review the design", "check the UI", or wants a comprehensive UI/UX review. Uses a 7-phase methodology covering interaction, responsiveness, accessibility, and more.

    Computed 9831,966

    K-Dense-AI/scientific-agent-skills

    dask

    Distributed computing for larger-than-RAM pandas/NumPy workflows. Use when you need to scale existing pandas/NumPy code beyond memory or across clusters. Best for parallel file processing, distributed ML, integration with existing pandas code. For out-of-core analytics on single machine use vaex; for in-memory speed use polars.