⚡AgentSkills
🔐 Cybersecurity · Application Security

Threat model a feature before building it

STRIDE-lite walkthrough producing mitigations wired into tickets before code exists.

intermediate~40 minSecurity EngineersAppSecDevSecOps

Steps

  1. 1Diagram the feature: actors, data flows, trust boundaries, stores
  2. 2Walk STRIDE per boundary: spoofing, tampering, repudiation, info-disclosure, DoS, elevation
  3. 3Rank findings by likelihood × impact; top items get design changes
  4. 4Write mitigations as acceptance criteria in implementation tickets
  5. 5Add abuse cases to the test plan alongside functional cases
  6. 6Revisit the model when architecture shifts, not just annually

Common Pitfalls

  • ▲Threat models as one-time compliance theater
  • ▲Trusting internal services implicitly across boundaries

Commands

Install with skills CLI
$ npx skills add aniruddhaadak80/skills --skill application-security-threat-model-feature
Install globally
$ npx skills add aniruddhaadak80/skills --skill application-security-threat-model-feature -g

Tags

#threat-modeling#appsec#cybersecurity#application-security

Related skills

Focused pass over authz, injection, secrets, and deserialization on risky diffs.

🔐 Cybersecurity·~35m

Generation, storage, rotation, and leak response for credentials humans inevitably touch.

🔐 Cybersecurity·~25m