Skip to main content
Back to the directory
openai/skillsSoftware EngineeringFrontend and Design

security-threat-model

Repository-grounded threat modeling that maps trust boundaries, assets, and abuse paths to concrete code evidence.

SkillJury keeps community verdicts, source metadata, and external repository signals in separate lanes so ranking data never pretends to be a review.

SkillJury verdict
Pending

No approved reviews yet

Would recommend
Pending

Waiting on enough review volume

Install signal
1

Weekly or total install activity from catalog data

Sign in to review
0 review requests
Install command
npx skills add https://github.com/openai/skills --skill security-threat-model
SkillJury does not have enough approved reviews to publish a community verdict yet. Source metadata and repository proof are still available above.
SkillJury Signal Summary

As of Apr 30, 2026, security-threat-model has 1 weekly installs, 0 community reviews on SkillJury. Community votes currently stand at 0 upvotes and 0 downvotes. Source: openai/skills. Canonical URL: https://skills.sh/openai/skills/security-threat-model.

Security audits
Gen Agent Trust HubPASS
SocketPASS
SnykPASS
About this skill
Repository-grounded threat modeling that maps trust boundaries, assets, and abuse paths to concrete code evidence. Deliver an actionable AppSec-grade threat model that is specific to the repository or a project path, not a generic checklist. Anchor every architectural claim to evidence in the repo and keep assumptions explicit. Prioritizing realistic attacker goals and concrete impacts over generic checklists. Only load the reference files you need. Keep the final result concise, grounded, and reviewable. - Enumerates entry points, data flows, and trust boundaries anchored to actual repository structure and configuration - Derives realistic attacker goals tied to specific assets (credentials, PII, integrity-critical state, compute resources) rather than generic checklists - Prioritizes threats using likelihood and impact reasoning, with explicit assumptions about deployment, authentication, and internet exposure - Recommends mitigations tied to specific components and control types (validation, rate limiting, secrets isolation, audit logging) with implementation hints - Requires user clarification on service context (environment, scale, auth model, data sensitivity) before finalizing priority rankings - Collect (or infer) inputs: - Repo root path and any in-scope paths. - Intended usage, deployment model, internet exposure, and auth expectations (if known).

Source description provided by the upstream listing. Community review signal and install context stay separate from this narrative layer.

Community reviews

Latest reviews

No community reviews yet. Be the first to review.

Browse this skill in context
FAQ
What does security-threat-model do?

Repository-grounded threat modeling that maps trust boundaries, assets, and abuse paths to concrete code evidence.

Is security-threat-model good?

security-threat-model does not have approved reviews yet, so SkillJury cannot publish a community verdict.

Which AI agents support security-threat-model?

security-threat-model currently lists compatibility with Codex, Cline, Skills CLI.

Is security-threat-model safe to install?

security-threat-model has been scanned by security audit providers tracked on SkillJury. Check the security audits section on this page for detailed results from Socket.dev and Snyk.

What are alternatives to security-threat-model?

Skills in the same category include grimoire-morpho-blue, conversation-memory, second-brain-ingest, zai-tts.

How do I install security-threat-model?

Run the following command to install security-threat-model: npx skills add https://github.com/openai/skills --skill security-threat-model

Related skills

More from openai/skills

Related skills

Alternatives in Software Engineering