🔐 Cybersecurity · Application Security
Threat model a feature before building it
STRIDE-lite walkthrough producing mitigations wired into tickets before code exists.
intermediate~40 minSecurity EngineersAppSecDevSecOps
Steps
- 1Diagram the feature: actors, data flows, trust boundaries, stores
- 2Walk STRIDE per boundary: spoofing, tampering, repudiation, info-disclosure, DoS, elevation
- 3Rank findings by likelihood × impact; top items get design changes
- 4Write mitigations as acceptance criteria in implementation tickets
- 5Add abuse cases to the test plan alongside functional cases
- 6Revisit the model when architecture shifts, not just annually
Common Pitfalls
- ▲Threat models as one-time compliance theater
- ▲Trusting internal services implicitly across boundaries
Commands
Install with skills CLI
$ npx skills add aniruddhaadak80/skills --skill application-security-threat-model-featureInstall globally
$ npx skills add aniruddhaadak80/skills --skill application-security-threat-model-feature -gTags
#threat-modeling#appsec#cybersecurity#application-security