Search

Threat modeling

224 skills found, page 4.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
145

Analyze and design a Flexport integration that separates REST v3 resources, MCP tools, webhook ingress, approval, and reconciliation.

jeremylongshore/tons-of-skills-marketplace2.8k—~1.1kAutomated safety check: PassMITyesterday
146

Analyze and harden Flexport credentials, tokens, webhook verification, data exposure, and mutation controls.

jeremylongshore/tons-of-skills-marketplace2.8k—~1.1kAutomated safety check: PassMITyesterday
147

Harden an Ideogram integration across credentials, untrusted media, content safety, copyright controls, storage, and tenant authorization.

jeremylongshore/tons-of-skills-marketplace2.8k—~1.2kAutomated safety check: PassMITyesterday
148

Harden Instantly API v2 keys, scopes, tenant boundaries, logs, webhooks, and operational access.

jeremylongshore/tons-of-skills-marketplace2.8k—~1.2kAutomated safety check: PassMITyesterday
149

Harden Linear credentials, OAuth, team access, webhook verification, logging, and rotation.

jeremylongshore/tons-of-skills-marketplace2.8k—~1.3kAutomated safety check: PassMITyesterday
150

Threat-model and harden Lucid API, Standard Import, editor extension, and data connector integrations.

jeremylongshore/tons-of-skills-marketplace2.8k—~1kAutomated safety check: PassMITyesterday
151

Threat-model Mistral credentials, untrusted content, model output, tools, files, and tenant access.

jeremylongshore/tons-of-skills-marketplace2.8k—~877Automated safety check: PassMITyesterday
152

Threat-model a Navan integration across identity, travel, expense, payment, file, and downstream systems.

jeremylongshore/tons-of-skills-marketplace2.8k—~963Automated safety check: PassMITyesterday
153

Threat-model a Procore integration across OAuth credentials, company routing, DMSA permissions, webhooks, files, logs, and revocation.

jeremylongshore/tons-of-skills-marketplace2.8k—~1.1kAutomated safety check: PassMITyesterday
154

Establish least-privilege OAuth, secret, webhook, data, card, and financial-write controls for a Ramp integration.

jeremylongshore/tons-of-skills-marketplace2.8k—~1.3kAutomated safety check: PassMITyesterday
155

Harden Runway keys, organization access, prompts, media, generated outputs, and support evidence.

jeremylongshore/tons-of-skills-marketplace2.8k—~1.3kAutomated safety check: PassMITyesterday
156

Threat-model a WebContainer or StackBlitz embed across host, runtime, user-code, filesystem, dependency, network, preview, secret, and persistence boundaries.

jeremylongshore/tons-of-skills-marketplace2.8k—~1.3kAutomated safety check: NotesMITyesterday
157

Harden Snagit and Camtasia automation around capture consent, license secrecy, local storage, share destinations, least privilege, and artifact review.

jeremylongshore/tons-of-skills-marketplace2.8k—~1.1kAutomated safety check: PassMITyesterday
158

Secure Together AI integrations with project-scoped keys, environment isolation, prompt/output data controls, bounded model behavior, safe logging, rotation, and incident response.

jeremylongshore/tons-of-skills-marketplace2.8k—~1kAutomated safety check: PassMITyesterday
159

Harden Webflow tokens, scopes, webhook verification, logs, and live-write boundaries.

jeremylongshore/tons-of-skills-marketplace2.8k—~1.3kAutomated safety check: PassMITyesterday
160

Identifies what could go wrong in a system before it is built or changed — the assets worth attacking, the entry points, the trust boundaries, and the controls that actually address the realistic…

cbrock84/headcount2k—~841Automated safety check: PassMIT23 days ago
161

STRIDE threat modeling, DREAD risk scoring, secret detection, and secure architecture design.

borghei/Claude-Skills891—~1.8kAutomated safety check: PassMIT4 days ago
162

Audit or harden a defined application-security attack surface when the user explicitly requests a security audit, vulnerability investigation, or scoped security-hardening pass.

swyxio/skills176—~962Automated safety check: PassMIT6 days ago
163
163.Cso

Chief Security Officer mode. An agent skill from mr-daedalium/ostack-saas.

mr-daedalium/ostack-saas114—~7.4kAutomated safety check: NotesMIT6 mo ago
164
164.Go

A skill your agent uses when writing, reviewing, testing, or shipping Go code and HTTP services: idioms, %w error wrapping, goroutine/context/errgroup concurrency, net/http 1.22 routing, log/slog…

ericrisco/rsc-harness180—~3.9kAutomated safety check: PassMITyesterday
165

A skill your agent uses when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has…

ericrisco/rsc-harness180—~2.8kAutomated safety check: NotesMITyesterday
166

Hack23 ISMS organization-wide compliance requirements, policy enforcement, audit preparation

Hack23/cia239—~1.9kAutomated safety check: PassApache-2.0yesterday
167

MCP gateway security patterns, token management, request validation, and audit logging for MCP communications

Hack23/cia239—~2.4kAutomated safety check: PassApache-2.0yesterday
168

Threat modeling before coding, STRIDE methodology, defense in depth, security controls in SDLC

Hack23/cia239—~1.9kAutomated safety check: PassApache-2.0yesterday
169

Maintain comprehensive security documentation including SECURITYARCHITECTURE.md, THREATMODEL.md per Hack23 ISMS standards

Hack23/cia239—~2.3kAutomated safety check: PassApache-2.0yesterday
170

Focused static audit of device firmware and IoT software for update, boot, provisioning, credential, debug-interface and device-communication boundary failures, using an ISVS-informed threat model.

alpha-omega-security/scrutineer242—~1.6kAutomated safety check: NotesMITyesterday
171

Audit package manager clients, registries, and proxies against a bundled threat model.

alpha-omega-security/scrutineer242—~1kAutomated safety check: NotesMITyesterday
172

Focused static audit of web applications and APIs for session, browser-origin, upload and business-workflow boundary failures, using an ASVS-informed threat model.

alpha-omega-security/scrutineer242—~1.3kAutomated safety check: NotesMITyesterday
173

Full security audit for public repositories across 12 attack surfaces: git history, secrets, CI/CD, containers, dependencies, licenses.

Mathews-Tom/armory329—~2.2kAutomated safety check: PassMIT5 days ago
174

Diagnose and operate Spring AI projects with version-aware Maven or Gradle checks for ChatClient, advisors, retrieval, conversation memory, tool/MCP boundaries, streaming, configuration, and…

magnus919/agent-skills115—~1.2kAutomated safety check: PassMITyesterday
175

Conduct LINDDUN privacy threat modeling across all seven categories: Linking, Identifying, Non-repudiation, Detecting, Data Disclosure, Unawareness, and Non-compliance.

mukul975/Privacy-Data-Protection-Skills301—~3.2kAutomated safety check: PassApache-2.06 mo ago
176

Comprehensive threat modeling for multi-agent systems using CSA MAESTRO 7-layer framework and OWASP Multi-Agentic System Threat Modeling Guide v1.0.

OWASP/secure-agent-playbook188—~835Automated safety check: NotesUnknown16 days ago
177

Build or challenge an application threat model from architecture, dataflows, identities, trust boundaries, business invariants, dependencies, and deployment context.

cyberful/cyberful135—~1.2kAutomated safety check: PassAGPL-3.01 mo ago
178

Generates complete conventional oncology bulk-transcriptome biomarker and hub-gene research designs from a user-provided cancer type and study direction.

aipoch/medical-research-skills1.9k—~4.6kAutomated safety check: PassMIT24 days ago
179

Derive a project's security contract from its source and docs, then emit it as structured data other skills can cite.

alpha-omega-security/scrutineer242—~6.8kAutomated safety check: PassMITyesterday
180
180.Verify

Re-run a finding's reproduction against current HEAD, test its attack tree, grade five fixed evidence criteria, and account for every matched design control.

alpha-omega-security/scrutineer242—~5.7kAutomated safety check: PassMITyesterday
181

Analyze attack surface analyzer operations. An agent skill from jeremylongshore/tons-of-skills-marketplace.

jeremylongshore/tons-of-skills-marketplace2.8k—~585Automated safety check: PassMITyesterday
182

Threat-model and harden a Mindtickle tenant and its identity, connector, API, content, and reporting integrations.

jeremylongshore/tons-of-skills-marketplace2.8k—~1.1kAutomated safety check: PassMITyesterday
183

Threat-model SerpAPI credentials, query data, result retention, browser exposure, logs, and ZeroTrace tradeoffs.

jeremylongshore/tons-of-skills-marketplace2.8k—~1.1kAutomated safety check: PassMITyesterday
184

Create threat model creator operations. An agent skill from jeremylongshore/tons-of-skills-marketplace.

jeremylongshore/tons-of-skills-marketplace2.8k—~573Automated safety check: PassMITyesterday
185

Produce a threat model — assets, ranked threats, mitigations, accepted risks.

jeremylongshore/tons-of-skills-marketplace2.8k—~1.6kAutomated safety check: NotesMITyesterday
186

Financial risk modeling including VaR, stress testing, and credit risk

wentorai/research-plugins2981 repo~2.1kAutomated safety check: PassMIT3 mo ago
187

Reusable writing-style contract for agent outputs (reports, ARCH docs, verdicts, threat models).

avelikiy/great_cto102—~1kAutomated safety check: PassMIT2 days ago
188

Produce a repository-grounded application security threat model with assets, boundaries, abuse paths, priorities, and mitigations.

nightly-labs/openbot489—~379Automated safety check: PassUnknownyesterday
189

Conduct systematic threat modeling using STRIDE framework, attack trees, and security architecture analysis for CIA platform

Hack23/cia239—~6.8kAutomated safety check: PassApache-2.0yesterday
190

Write a STRIDE-based threat model for a service or feature. An agent skill from mohitagw15856/pm-claude-skills.

mohitagw15856/pm-claude-skills1.4k—~3.8kAutomated safety check: PassMIT2 days ago
191

Threat-model a system or feature to find where it could be attacked, before you build it.

mohitagw15856/pm-claude-skills1.4k—~911Automated safety check: PassMIT2 days ago
192

Assess the physical attack surface of embedded devices — finding and using UART consoles, JTAG/SWD debug, and SPI/I2C flash; dumping firmware off-chip; triaging secure boot; and studying sub-GHz RF…

trilwu/secskills157—~1.8kAutomated safety check: PassMIT1 mo ago