Search
Threat modeling
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 193 | 193.Threat Model Threat modeling and attack surface analysis. An agent skill from hashgraph-online/awesome-codex-plugins. | hashgraph-online/ | 1.3k | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 194 | 194.Vuln Scan Systematic vulnerability scan across injection, auth, data exposure, and dependencies — traced by reading code, not grepping for keywords. | hashgraph-online/ | 1.3k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 195 | Security Ownership Map workflow skill. An agent skill from diegosouzapw/awesome-omni-skills. | diegosouzapw/ | 159 | — | ~4.6k | Automated safety check: Pass | Apache-2.0 | 3 mo ago |
| 196 | 196.QA Methodology Design and apply QA methodology for software teams: test strategy, regression testing, CI failure triage, test automation, quality gates and metrics, risk-based testing, exploratory testing, test… | magnus919/ | 115 | — | ~3.2k | Automated safety check: Pass | MIT | yesterday |
| 197 | Vulnerability review, threat modeling, OWASP patterns, and secure coding assessment. | rsmdt/ | 560 | — | ~1.3k | Automated safety check: Pass | MIT | 2 mo ago |
| 198 | 198.Security Review AI-powered security analysis of code changes — traces data flow, detects injection, auth bypass, secrets exposure, and unsafe deserialization across files. | danielvm-git/ | 260 | — | ~1.5k | Automated safety check: Pass | MIT | 19 days ago |
| 199 | Plans and runs authorized reconnaissance to enumerate a target's external attack surface (DNS, subdomains, ports, web tech) and produces a prioritized report. | criptogus/ | 288 | — | ~1.2k | Automated safety check: Pass | CC-BY-SA-4.0 | 2 days ago |
| 200 | Generate a STRIDE-based security threat model for a repository. | Factory-AI/ | 111 | — | ~2.1k | Automated safety check: Pass | No licence | 4 days ago |
| 201 | Trigger Pattern Any external module interaction detected in attacksurface.md - Inject Into Breadth agents (merged via M5 hierarchy) | PlamenTSV/ | 303 | — | ~1.1k | Automated safety check: Pass | MIT | 14 days ago |
| 202 | 202.Security Auditor Assess vulnerabilities and audit for security compliance using OWASP and STRIDE methodology — a user-invoked Security Auditor workflow. | dralgorhythm/ | 125 | — | ~496 | Automated safety check: Pass | No licence | 2 mo ago |
| 203 | A skill your agent uses when drafting an ACM CCS rebuttal during the HotCRP author-response window, covering threat-model defenses, adaptive-attack objections, ethics and disclosure questions… | brycewang-stanford/ | 1.2k | — | ~949 | Automated safety check: Pass | MIT | 14 days ago |
| 204 | A skill your agent uses when strengthening ACM CCS reproducibility evidence, including the artifact-availability posture, threat-model-to-evidence mapping, attack reproduction steps, defense… | brycewang-stanford/ | 1.2k | — | ~903 | Automated safety check: Pass | MIT | 14 days ago |
| 205 | A skill your agent uses when deciding whether a security project fits ACM CCS versus IEEE S&P, USENIX Security, NDSS, PETS, or a crypto/theory venue, identifying the security contribution type, and… | brycewang-stanford/ | 1.2k | — | ~945 | Automated safety check: Pass | MIT | 14 days ago |
| 206 | A skill your agent uses when revising an ACM CCS paper for a precise threat model, calibrated attack/defense claims, 12-page ACM sigconf compression, double-blind wording, adaptive-evaluation… | brycewang-stanford/ | 1.2k | — | ~918 | Automated safety check: Pass | MIT | 14 days ago |
| 207 | A skill your agent uses when drafting the IEEE S&P (Oakland) rebuttal for second-round papers or the response plan for a Revise decision, including triaging reviews under the ~5-day window… | brycewang-stanford/ | 1.2k | — | ~1.3k | Automated safety check: Pass | MIT | 14 days ago |
| 208 | A skill your agent uses when deciding whether a security or privacy project belongs at IEEE S&P (Oakland), including the threat-model test, SoK fit, routing among USENIX Security, CCS, NDSS, PETS… | brycewang-stanford/ | 1.2k | — | ~1.3k | Automated safety check: Pass | MIT | 14 days ago |
| 209 | A skill your agent uses when writing or revising an IEEE S&P (Oakland) paper's prose, including the threat-model-first structure, calibrating security claims to evaluated boundaries, the first-round… | brycewang-stanford/ | 1.2k | — | ~1.2k | Automated safety check: Pass | MIT | 14 days ago |
| 210 | A skill your agent uses when revising an ISSTA paper for a clear testing/analysis contribution, covering the threat-model-then-technique structure, the evaluation contract, a threats-to-validity… | brycewang-stanford/ | 1.2k | — | ~1.1k | Automated safety check: Pass | MIT | 14 days ago |
| 211 | A skill your agent uses to rehearse peer review before submitting — a calibrated Associate Editor desk-screen plus 2–3 distinct-lens referees for the target venue, adversarially verified and… | brycewang-stanford/ | 1.2k | — | ~707 | Automated safety check: Pass | MIT | 14 days ago |
| 212 | A skill your agent uses when designing or auditing the evaluation of a USENIX Security Symposium paper — building threat-model-faithful experiments, adaptive-attacker analysis for defenses… | brycewang-stanford/ | 1.2k | — | ~1.5k | Automated safety check: Pass | MIT | 14 days ago |
| 213 | A skill your agent uses when drafting or revising prose for a USENIX Security Symposium paper — threat-model-first structure, calibrated security claims, disclosure narrative woven into the text… | brycewang-stanford/ | 1.2k | — | ~1.3k | Automated safety check: Pass | MIT | 14 days ago |
| 214 | 214.Security Audit Perform a broad, authorized security audit across application, infrastructure, identity, dependencies, and operations. | seb1n/ | 206 | — | ~2.4k | Automated safety check: Notes | MIT | 2 mo ago |
| 215 | 215.Threat Modeling Conduct structured threat modeling for software systems using established methodologies to identify, prioritize, and mitigate security threats before they are exploited. | seb1n/ | 206 | — | ~3.1k | Automated safety check: Pass | MIT | 2 mo ago |
| 216 | A skill your agent uses when the user asks for a deep, exhaustive, multi-pass, or variance-reducing repository-wide Codex Security scan. | CoWork-OS/ | 477 | — | ~8.6k | Automated safety check: Pass | MIT | yesterday |
| 217 | A skill your agent uses when analyzing, selecting, validating, or communicating models for insurance, actuarial, financial-risk, or other consequential uncertain outcomes. | magnus919/ | 115 | — | ~3.2k | Automated safety check: Pass | MIT | yesterday |
| 218 | 218.Defender Easm Guidance for Microsoft Defender External Attack Surface Management (Defender EASM) — discovers and inventories an organization's internet-facing assets (domains, hosts, IPs, SSL certs, ASNs, web… | vinayaklatthe/ | 175 | — | ~1.9k | Automated safety check: Pass | MIT | 3 mo ago |
| 219 | Guidance for Microsoft Defender for Endpoint (MDE) — enterprise endpoint security with next-gen AV, EDR, attack surface reduction (ASR), Defender Vulnerability Management, automated investigation… | vinayaklatthe/ | 175 | — | ~2.3k | Automated safety check: Pass | MIT | 3 mo ago |
| 220 | 220.Threat Modelling Guidance for threat modelling using STRIDE and the Microsoft Security Development Lifecycle (SDL). | vinayaklatthe/ | 175 | — | ~1.8k | Automated safety check: Pass | MIT | 3 mo ago |
| 221 | Complete guide to LINDDUN privacy threat modeling methodology covering seven threat categories: Linking, Identifying, Non-repudiation, Detecting, Data Disclosure, Unawareness, and Non-compliance. | mukul975/ | 301 | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | 6 mo ago |
| 222 | 222.Security Auditor MASTER SECURITY: OWASP Top 10, SAST/DAST, PenTest. An agent skill from Dokhacgiakhoa/Agent-Skills-4-Vibe-Coding-CLI. | Dokhacgiakhoa/ | 508 | — | ~440 | Automated safety check: Pass | Unknown | 4 mo ago |
| 223 | Advanced vulnerability analysis principles. An agent skill from Dokhacgiakhoa/Agent-Skills-4-Vibe-Coding-CLI. | Dokhacgiakhoa/ | 508 | — | ~494 | Automated safety check: Pass | Unknown | 4 mo ago |
| 224 | Expert knowledge for Azure External Attack Surface Management development including configuration. | MicrosoftDocs/ | 776 | — | ~935 | Automated safety check: Pass | CC-BY-4.0 | 5 days ago |