Skip to content
Built here

STRIDE threat model

/security--threat-model

/security--threat-model is a Claude Code skill in the Code section. Analyzes your repo's architecture and writes threat-model.md with a data-flow diagram, rated STRIDE threats and a top-5 action list.

Author's description

Threat model with STRIDE: assets, trust boundaries, attack surface, mitigations

Use it when

  • You are designing or reviewing an architecture and want to know what could go wrong
  • You need to prioritize which security issues to fix first
  • You are preparing an external assessment and want a documented model to start from

Not for

  • Finding specific vulnerabilities line by line: use the security audit for that
  • Replacing the judgment of a security team

What you get

A threat-model.md file with a Mermaid diagram, a threat table (element, STRIDE category, threat, rating, mitigation) and a top-5 action list.

How to ask for it

  • /security--threat-model build a threat model for my architecture
  • /security--threat-model identify the trust boundaries in this system
  • /security--threat-model what's the attack surface of my API?

Install

curl -fsSL https://raw.githubusercontent.com/sgomez-dev/claude-skills/main/install.sh | bash

After installing with the script, type /security--threat-model. Using Cursor, Windsurf or Codex? Platform guides

Questions about this skill

What is STRIDE?
A method that walks through six threat types: spoofing, tampering, repudiation, information disclosure, denial of service and elevation of privilege.
Can I model just part of the system?
Yes. If the scope is unclear it asks whether to model a feature, a service or the whole system.
Do I need to redo it when the architecture changes?
Yes, you should revisit it: the skill treats a threat model as a living document to update when the architecture changes.

Demo coming soon

↑↓ move · Enter open · Esc close