# STRIDE threat model (/security--threat-model)

/security--threat-model is a Claude Code skill in the Code section. Analyzes your repo's architecture and writes threat-model.md with a data-flow diagram, rated STRIDE threats and a top-5 action list.

- Web version: https://skills.sgomez.dev/en/s/security--threat-model
- Section: [Code](https://skills.sgomez.dev/en/code.md)
- Author: Santiago Gómez de la Torre
- License: MIT
- Source: https://github.com/sgomez-dev/claude-skills/blob/main/skills/security/threat-model.md
- Updated 10 Jul 2026

## Use it when

- You are designing or reviewing an architecture and want to know what could go wrong
- You need to prioritize which security issues to fix first
- You are preparing an external assessment and want a documented model to start from

## Not for

- Finding specific vulnerabilities line by line: use the security audit for that
- Replacing the judgment of a security team

## What you get

A threat-model.md file with a Mermaid diagram, a threat table (element, STRIDE category, threat, rating, mitigation) and a top-5 action list.

## How to ask for it

- `/security--threat-model build a threat model for my architecture`
- `/security--threat-model identify the trust boundaries in this system`
- `/security--threat-model what's the attack surface of my API?`

## Install

macOS · Linux:

```
curl -fsSL https://raw.githubusercontent.com/sgomez-dev/claude-skills/main/install.sh | bash
```

Windows:

```
irm https://raw.githubusercontent.com/sgomez-dev/claude-skills/main/install.ps1 | iex
```

Claude Code plugin:

```
/plugin marketplace add sgomez-dev/claude-skills
/plugin install security-skills@claude-skills-collection
```

## Permissions

- Reads: `**/*`
- Writes: `threat-model*.md`
- Runs: —
- Network: No
- Destructive: No

## Author's description

Threat model with STRIDE: assets, trust boundaries, attack surface, mitigations

## Questions about this skill

### What is STRIDE?

A method that walks through six threat types: spoofing, tampering, repudiation, information disclosure, denial of service and elevation of privilege.

### Can I model just part of the system?

Yes. If the scope is unclear it asks whether to model a feature, a service or the whole system.

### Do I need to redo it when the architecture changes?

Yes, you should revisit it: the skill treats a threat model as a living document to update when the architecture changes.


- [How we review this](https://skills.sgomez.dev/en/methodology.md)
